Commit 37ef809
File tree
3 files changed
- packages/@vue
- cli-ui
- package.jsonhas 1 comment
- yarn.lockhas 2 comments
3 files changed
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 |
| - | |
| 29 | + | |
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
|
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
53 | 53 |
| |
54 | 54 |
| |
55 | 55 |
| |
56 |
| - | |
| 56 | + Has a conversation. Original line has a conversation. | |
57 | 57 |
| |
58 | 58 |
| |
59 | 59 |
| |
|
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7158 | 7158 |
| |
7159 | 7159 |
| |
7160 | 7160 |
| |
7161 |
| - | |
| 7161 | + | |
7162 | 7162 |
| |
7163 | 7163 |
| |
7164 | 7164 |
| |
| |||
9412 | 9412 |
| |
9413 | 9413 |
| |
9414 | 9414 |
| |
| 9415 | + | |
| 9416 | + | |
| 9417 | + | |
| 9418 | + | |
| 9419 | + | |
9415 | 9420 |
| |
9416 | 9421 |
| |
9417 | 9422 |
| |
| |||
12821 | 12826 |
| |
12822 | 12827 |
| |
12823 | 12828 |
| |
12824 |
| - | |
| 12829 | + | |
12825 | 12830 |
| |
12826 | 12831 |
| |
12827 | 12832 |
| |
12828 | 12833 |
| |
12829 |
| - | |
| 12834 | + | |
12830 | 12835 |
| |
12831 | 12836 |
| |
12832 | 12837 |
| |
| |||
14919 | 14924 |
| |
14920 | 14925 |
| |
14921 | 14926 |
| |
14922 |
| - | |
| 14927 | + | |
14923 | 14928 |
| |
14924 | 14929 |
| |
14925 | 14930 |
| |
| |||
14928 | 14933 |
| |
14929 | 14934 |
| |
14930 | 14935 |
| |
| 14936 | + | |
| 14937 | + Has a conversation. Original line has a conversation. | |
| 14938 | + | |
| 14939 | + | |
| 14940 | + | |
| 14941 | + | |
| 14942 | + | |
| 14943 | + | |
| 14944 | + | |
| 14945 | + | |
| 14946 | + | |
14931 | 14947 |
| |
14932 | 14948 |
| |
14933 | 14949 |
| |
| |||
15861 | 15877 |
| |
15862 | 15878 |
| |
15863 | 15879 |
| |
| 15880 | + Has a conversation. Original line has a conversation. | |
| 15881 | + | |
| 15882 | + | |
| 15883 | + | |
| 15884 | + | |
15864 | 15885 |
| |
15865 | 15886 |
| |
15866 | 15887 |
| |
|
6 commit comments
I have no opinion on the "protestware" thing.
But shipping it in a patch, and without a corresponding tag on GitHub, is very unprofessional.
I have to lock it for now.
I have no opinion on the "protestware" thing.
But shipping it in a patch, and without a corresponding tag on GitHub, is very unprofessional. I have to lock it for now.
When I first saw the "WITH-LOVE-FROM-AMERICA.txt" file on my desktop (created by the peacenotwar dependency of node-ipc 9.2.2), I said to myself... "OK, so I just installed some ransomware. Nice."
Thank you @sodatea for fixing this quickly!
@sodatea, did you want to lock node-ipc@9.2.1?
upd: i see, you have fixed it later
I have no opinion on the "protestware" thing.
But shipping it in a patch, and without a corresponding tag on GitHub, is very unprofessional. I have to lock it for now.
It is important to note that this particular case isn't just some random protestware event, the initial version was intentionally destructive and caused damage, even though it was only active briefly. This is simply naive and unacceptable behaviour from the maintainer of node-ipc
, and while I too don't really have an opinion on protestware, I do not think this behaviour is at all tolerable.
The current version of the node-ipc
code is not available on GitHub from what I could tell. I used RunKit to explore the latest state of the code to validate that the malicious code is gone. There is still code to place a text file in users' OneDrive folders and their Desktop folders.
In other words, it's really good that this is now frozen, but, it doesn't seem like relying on it later is all that safe.
Some more detailed information can be found here: https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability
For those who need it, we're currently maintaining a maintenance fork over at https://github.com/achrinza/node-ipc for both v9 and v10/v11
@Hexcede The currently used locked version of node-ipc 9.2.1 is still not safe due to nested dependencies from the same author, see discussion #7051 (comment)