Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[eas-cli] Upgrade @expo/multipart-body-parser #2751

Merged

Conversation

wschurman
Copy link
Member

@wschurman wschurman commented Dec 9, 2024

Why

There's a CVE in dicer and there's no fix planned: GHSA-wm7h-9275-46v2
mscdex/dicer#22

@expo/multipart-body-parser used dicer until 2.0.0.

Closes ENG-14330.
Fixes expo/expo#20225.

How

Version 2.0.0 of @expo/multipart-body-parser moved it off of dicer.

Test Plan

Publish a code signed update (the part of eas-cli that uses this library):

neas update --private-key-path keys/private-key.pem

Copy link
Member Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

Copy link

linear bot commented Dec 9, 2024

@wschurman wschurman marked this pull request as ready for review December 9, 2024 20:17
Copy link

github-actions bot commented Dec 9, 2024

Subscribed to pull request

File Patterns Mentions
**/* @szdziedzic, @khamilowicz, @sjchmiela, @radoslawkrzemien

Generated by CodeMention

@wschurman wschurman force-pushed the @wschurman/12-09-_eas-cli_upgrade_expo/multipart-body-parser branch from 665f05a to d178d04 Compare December 9, 2024 20:19
Copy link

github-actions bot commented Dec 9, 2024

Size Change: -915 B (0%)

Total Size: 53.4 MB

Filename Size Change
./packages/eas-cli/dist/eas-linux-x64.tar.gz 53.4 MB -915 B (0%)

compressed-size-action

Copy link

codecov bot commented Dec 9, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 52.51%. Comparing base (3740ee4) to head (3a9d7bf).
Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2751   +/-   ##
=======================================
  Coverage   52.51%   52.51%           
=======================================
  Files         583      583           
  Lines       22576    22576           
  Branches     4447     4447           
=======================================
  Hits        11854    11854           
  Misses      10687    10687           
  Partials       35       35           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@@ -11,6 +11,7 @@ This is the log of notable changes to EAS CLI and related packages.
### 🐛 Bug fixes

- Bump `@expo/apple-utils` to fix sending two-factor authentication codes via SMS. ([#2750](https://github.com/expo/eas-cli/pull/2750) by [@EvanBacon](https://github.com/EvanBacon))
- Upgrade @expo/multipart-body-parser. ([#2751](https://github.com/expo/eas-cli/pull/2751) by [@wschurman](https://github.com/wschurman))
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We will probably need to rebase this PR before merging so the changelog entry is placed under the correct release (a new release was published)

@wschurman wschurman force-pushed the @wschurman/12-09-_eas-cli_upgrade_expo/multipart-body-parser branch from d178d04 to 3a9d7bf Compare December 10, 2024 18:09
Copy link

✅ Thank you for adding the changelog entry!

@wschurman wschurman merged commit 8d35745 into main Dec 10, 2024
7 checks passed
@wschurman wschurman deleted the @wschurman/12-09-_eas-cli_upgrade_expo/multipart-body-parser branch December 10, 2024 18:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

High vulnerability in dicer used by @expo/multipart-body-parser
2 participants