Details
-
New Feature
-
Status: Closed (View Workflow)
-
P3
-
Resolution: Done
-
None
-
None
-
-
Stripes Force
-
Description
https://github.com/mysticatea/eslint-utils/security/advisories/GHSA-3gx7-xhv7-5mx3 says:
'getStaticValue' function can execute arbitrary code
This can be fixed by updating eslint to >= 6.2.1 or updating eslint-util to >= 1.4.1.
Some examples which eslint version currently is in use:
5.6.1 https://github.com/folio-org/platform-core/blob/master/package.json#L45
4.19.1 https://github.com/folio-org/platform-complete/blob/master/package.json#L62
5.12.0: https://github.com/folio-org/eslint-config-stripes/blob/master/package.json#L16
5.0.0: https://github.com/folio-org/stripes/blob/master/package.json#L34
This should be fixed even if FOLIO is not affected by this issue. Otherwise people get used to ignore the GitHub security warnings and miss relevant security issues.
TestRail: Results
Attachments
Issue Links
- is cloned by
-
UXPROD-2340 Remaining - Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
- relates to
-
UIU-1446 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
ERM-729 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
STCOM-642 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
STCON-93 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
STCOR-412 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
STRIPESFF-1 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
STSMACOM-297 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIAC-13 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UICAT-64 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UICHKIN-150 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UICHKOUT-586 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UICIRC-414 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UICR-17 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UID-20 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIDATIMP-370 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1: main rules
-
- Closed
-
-
UIDATIMP-376 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1: secondary rules
-
- Closed
-
-
UIEH-818 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIEUS-127 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIF-174 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIIN-940 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIMPROF-41 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UINOTES-70 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UINV-112 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIOR-499 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIORGS-144 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIPCITEM-6 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIPFCONT-3 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIPFI-7 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIPFIMP-8 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIPFINT-4 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIPFO-7 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIPFPOL-5 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIPFU-24 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIREC-40 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UIREQ-407 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UISP-13 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UITEN-72 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-
-
UITEST-73 Security update eslint to >= 6.2.1 or eslint-util >= 1.4.1
-
- Closed
-