← All tasks
javascriptsalesforce/tough-cookie #134Not a task: already works

Reliance on psl < 1.1.29 could pull in malicious code

envgap__salesforce__tough-cookie-134

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
296a98f911f37b84ed625f5545594d49b73ef61d
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

salesforce/tough-cookie #134 · read the original issue
The psl module is used as a dependency with semver `^1.1.28`. Prior to psl version 1.1.30, psl had a development dependency on event-stream with semver `^3.3.4`. event-stream 3.3.5 included a dependency on flatmap-stream, which contained [malicious code](https://github.com/dominictarr/event-stream/issues/116) designed to steal bitcoins. As such, if when building tough-cookie a version of psl is used prior to 1.1.30 (which is possible due to the semver specification), and psl pulls in event-stream 3.3.5 (also possible), the malicious code would be included.



While npm has removed the version containing malicious code, requiring the latest version of psl will also require event-stream 3.3.4, which will protect people who might have cached copies of event-stream 3.3.5.



Sorry if this is confusing -- there are lots of version numbers here!
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]