← All tasks
javascriptcure53/DOMPurify #427Not a task: already works

2.0.9 overrides adds a node binary to the PATH in npx calls

envgap__cure53__DOMPurify-427

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
22ea2c2b3a032a3e0c0ce6e9f424c18b8480a9b8
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

cure53/DOMPurify #427 · read the original issue
The 2.0.9 point release installs a `node` binary in the `node_modules/.bin`. In the event that your project adds `node_modules/.bin` to the current PATH, that `node` will take precedence over the system node. In my case I use `npx` which does this PATH management automatically.



This is due to the [commit](https://github.com/cure53/DOMPurify/commit/b26420eef1b10cb8116ca1b774da41896a930d34) that adds the `node` npm package as a dependency. Is it an absolute requirement or can it be installed as a dev dependency?



Example of this unexpected behavior:



```

~/dev/testpackage

❯ npm install dompurify@2.0.7

+ dompurify@2.0.7

added 1 package from 1 contributor and audited 1 package in 0.762s

found 0 vulnerabilities





~/dev/testpackage took 2s

❯ npx node -v

v10.18.0



~/dev/testpackage

❯ npm install dompurify@2.0.9



> node@13.13.0 preinstall /Users/dustym/dev/testpackage/node_modules/node

> node installArchSpecificPackage



+ node-darwin-x64@13.13.0

added 1 package in 5.234s

found 0 vulnerabilities



+ dompurify@2.0.9

added 3 packages from 2 contributors, updated 1 package and audited 4 packages in 7.376s

found 0 vulnerabilities





~/dev/testpackage took 8s

❯ npx node -v

v13.13.0

```
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]