2.0.9 overrides adds a node binary to the PATH in npx calls
envgap__cure53__DOMPurify-427
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
22ea2c2b3a032a3e0c0ce6e9f424c18b8480a9b8- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
cure53/DOMPurify #427 · read the original issue
The 2.0.9 point release installs a `node` binary in the `node_modules/.bin`. In the event that your project adds `node_modules/.bin` to the current PATH, that `node` will take precedence over the system node. In my case I use `npx` which does this PATH management automatically. This is due to the [commit](https://github.com/cure53/DOMPurify/commit/b26420eef1b10cb8116ca1b774da41896a930d34) that adds the `node` npm package as a dependency. Is it an absolute requirement or can it be installed as a dev dependency? Example of this unexpected behavior: ``` ~/dev/testpackage ❯ npm install dompurify@2.0.7 + dompurify@2.0.7 added 1 package from 1 contributor and audited 1 package in 0.762s found 0 vulnerabilities ~/dev/testpackage took 2s ❯ npx node -v v10.18.0 ~/dev/testpackage ❯ npm install dompurify@2.0.9 > node@13.13.0 preinstall /Users/dustym/dev/testpackage/node_modules/node > node installArchSpecificPackage + node-darwin-x64@13.13.0 added 1 package in 5.234s found 0 vulnerabilities + dompurify@2.0.9 added 3 packages from 2 contributors, updated 1 package and audited 4 packages in 7.376s found 0 vulnerabilities ~/dev/testpackage took 8s ❯ npx node -v v13.13.0 ```
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]