Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backporting debug package DDoS Fix to babel 6.xx.x #6521

Closed
dkotin-cs opened this issue Oct 20, 2017 · 4 comments
Closed

Backporting debug package DDoS Fix to babel 6.xx.x #6521

dkotin-cs opened this issue Oct 20, 2017 · 4 comments
Labels
outdated A closed issue/PR that is archived due to age. Recommended to make a new issue

Comments

@dkotin-cs
Copy link

Hi,

Nsp check reveals https://nodesecurity.io/advisories/534 for any project using babel-core v6.26.0. Vision media has resolved the issue in v2.6.9 and v.3.1.0 of their package (debug-js/debug#504 )

Is it possible to release a corresponding update to babel core for those of us on 6.xx.x while v7 is getting stabilized?

Thanks

@babel-bot
Copy link
Collaborator

Hey @dkotin-cs! We really appreciate you taking the time to report an issue. The collaborators
on this project attempt to help as many people as possible, but we're a limited number of volunteers,
so it's possible this won't be addressed swiftly.

If you need any help, or just have general Babel or JavaScript questions, we have a vibrant Slack
community that typically always has someone willing to help. You can sign-up here
for an invite.

@nicolo-ribaudo
Copy link
Member

Hi,
Babel the dependency on the debug package is specified as ^2.6.8, so if you delete the node_modules folder and run npm install, it should download v2.6.9

@dkotin-cs
Copy link
Author

Thanks! I'll give that a crack and report on what happens

@dkotin-cs
Copy link
Author

dkotin-cs commented Oct 20, 2017

It worked! For future readers: I was on an old version of npm so package-lock wasn't being properly updated. Make sure you update node and npm first

@lock lock bot added the outdated A closed issue/PR that is archived due to age. Recommended to make a new issue label May 1, 2018
@lock lock bot locked as resolved and limited conversation to collaborators May 1, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
outdated A closed issue/PR that is archived due to age. Recommended to make a new issue
Projects
None yet
Development

No branches or pull requests

3 participants