Open greenkeeper[bot] opened 7 years ago
After pinning to 1.8.0 your tests are still failing. The reported issue might not affect your project. These imprecisions are caused by inconsistent test results.
Your tests are still failing with this version. Compare the changes 🚨
Your tests are still failing with this version. Compare the changes 🚨
Your tests are still failing with this version. Compare the changes 🚨
lib/node_modules
)dependency
bower was updated from 1.8.4
to 1.8.6
.Your tests are still failing with this version. Compare changes
Fix Zip Slip Vulnerability of decompress-zip package: https://snyk.io/research/zip-slip-vulnerability
Note: v1.8.5 has been unpublished because of missing files
dependency
bower was updated from 1.8.6
to 1.8.7
.Your tests are still failing with this version. Compare changes
Fixes side effect of fix from v1.8.6 that caused improper permissions for extracted folders
dependency
bower was updated from 1.8.7
to 1.8.8
.Your tests are still failing with this version. Compare changes
Fix vulnerability related to extracting .tar.gz files that has similar effect to Zip Slip
Vulnerability is similar to Zip Slip allows for overriding and creating arbitrary files on filesystem
Needlessly to say, please upgrade this this version of Bower
Version 1.8.1 of bower just got published.
This version is covered by your current version range and after updating it in your project the build failed.
bower is a direct dependency of this project this is very likely breaking your project right now. If other packages depend on you it’s very likely also breaking them. I recommend you give this issue a very high priority. I’m sure you can resolve this :muscle:
Status Details
- ❌ **continuous-integration/codeship** Build failed [Details](https://app.codeship.com/projects/25301/builds/28413222)Not sure how things should work exactly?
There is a collection of [frequently asked questions](https://greenkeeper.io/faq.html) and of course you may always [ask my humans](https://github.com/greenkeeperio/greenkeeper/issues/new).Your Greenkeeper Bot :palm_tree: