Skip to content

Bump execa to resolve security vulnerability #7

@groenroos

Description

@groenroos

The 1.0.0 version of the execa dependency has a dependency for cross-spawn@^6.0.0, but this version of cross-spawn is insecure (CVE-2024-21538).

@currents/commit-info@1.0.0 requires cross-spawn@^6.0.0 via execa@1.0.0
No patched version available for cross-spawn

The vulnerability is fixed in cross-spawn@7.0.5. Later versions of execa do call for cross-spawn@^7.0.3, which could resolve to 7.0.5.

Thus, this project's dependency on execa should be bumped to at least the earliest version that allows for cross-spawn@7.0.5 to be installed. The earliest version of execa that calls for cross-spawn@^7.0.0 is execa@^3.0.0.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions