Skip to content

Fix command injection in yarn metadata lookup - #63

Merged
orta merged 2 commits into
orta:mainfrom
Dremig:main
May 16, 2026
Merged

Fix command injection in yarn metadata lookup#63
orta merged 2 commits into
orta:mainfrom
Dremig:main

Conversation

@Dremig

@Dremig Dremig commented May 15, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@glensc

glensc commented May 15, 2026

Copy link
Copy Markdown
Contributor

Fixing tests is in a separate mr:

you should cherry-pick it at least

also, never create pr from your main branch.

@glensc

glensc commented May 15, 2026

Copy link
Copy Markdown
Contributor

description missing

@glensc

glensc commented May 15, 2026

Copy link
Copy Markdown
Contributor

perhaps commit fix and test update separately

@orta

orta commented May 16, 2026

Copy link
Copy Markdown
Owner

Thanks @Dremig - this is a useful PR! Ignore the above feedback, I'll get this merged 👍🏻

@orta
orta merged commit 96c54ae into orta:main May 16, 2026
@orta

orta commented May 16, 2026

Copy link
Copy Markdown
Owner

Shipped as 1.7.0

@Dremig

Dremig commented May 16, 2026

Copy link
Copy Markdown
Contributor Author

Thanks @orta for reviewing, merging, and shipping this so quickly.

Apologies to @glensc and the maintainers for opening the PR without a proper description and from my main branch. This came out of a security-analysis tool I was running against public repositories, and after opening the PR I didn’t keep up with the discussion promptly. I didn’t mean to ignore the feedback or create extra work for the maintainers.

Wish you a good day!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants