Fix HIGH: override @xmldom/xmldom pour corriger 4 CVE #74
Labels
No labels
autopilot:pending-human
source:analyste
source:defenseur
source:human
source:medic
status:approved
status:blocked
status:in-progress
status:needs-clarification
status:needs-fix
status:ready
status:review
status:triage
type:bug
type:feature
type:infra
type:refactor
type:schema
type:security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: maximus/simpl-liste#74
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description
Ajouter un override
@xmldom/xmldom: ^0.8.13danspackage.jsonpour corriger 4 CVE dans les chaines de build Expo CLI et iOS (xcode).Fichiers concernes
package.json— ajouter la cle dansoverridespackage-lock.json— regenere parnpm installCVE adressees
Plan dimplementation
package.jsonpour ajouter"@xmldom/xmldom": "^0.8.13"dans lobjetoverridesexistant.npm installpour regenererpackage-lock.json.npm ls @xmldom/xmldomne liste plus 0.8.12 (doit afficher >=0.8.13).npx tsc --noEmitdoit passer sans erreur.timeout 10 npm startdoit demarrer Metro sans erreur dimport ni crash.status:review.Criteres dacceptation
package.jsoncontient"@xmldom/xmldom": "^0.8.13"dansoverrides.npm ls @xmldom/xmldomnaffiche que des versions>=0.8.13.npx tsc --noEmitpasse sans erreur.npm startdemarre Metro bundler sans erreur.npm audit --json | jq .vulnerabilities["@xmldom/xmldom"]retournenull.package-lock.jsonest commit dans le meme commit quepackage.json.Spec source
spec-plan-vuln-simpl-liste.md— Issue A