← All tasks
javascriptbrianc/node-postgres #2786Not a task: not reproduced

Security vulnerability in libpq thus dependency tree issue: pg -> pg-native -> libpq

envgap__brianc__node-postgres-2786

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
3e53d06cd891797469ebdd2f8a669183ba6224f6
Manifest
packages/pg/package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

brianc/node-postgres #2786 · read the original issue
pg depends on pg-native. pg-native has a high severity vulnerability issue with its version of libpq. Thus 'npm audit fix' does not work. Or with '--force' flag breaks the build.



Will install pg@8.3.3, which is a breaking change

node_modules/libpq

  pg-native  *

  Depends on vulnerable versions of libpq

  node_modules/pg-native

    pg  >=8.4.0

    Depends on vulnerable versions of pg-native

    node_modules/pg



Just registering here so it is logged
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]