Skip to content

Bump execa to resolve security vulnerability #7

@groenroos

Description

@groenroos

The 1.0.0 version of the execa dependency has a dependency for cross-spawn@^6.0.0, but this version of cross-spawn is insecure (CVE-2024-21538).

@currents/commit-info@1.0.0 requires cross-spawn@^6.0.0 via execa@1.0.0
No patched version available for cross-spawn

The vulnerability is fixed in cross-spawn@7.0.5. Later versions of execa do call for cross-spawn@^7.0.3, which could resolve to 7.0.5.

Thus, this project's dependency on execa should be bumped to at least the earliest version that allows for cross-spawn@7.0.5 to be installed. The earliest version of execa that calls for cross-spawn@^7.0.0 is execa@^3.0.0.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions