fix: address CVE-2022-24434, GHSA-wm7h-9275-46v2 caused by dicer #3420
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The process for this fix was to:
yarn why -R dicer
dicer indirectly (transient dependencies)
yarn up multer --exact
yarn up express-openapi-validator --exact
yarn why -R dicer
at this point shows thatdicer has been eliminated from the dependency tree completely.
https://github.com/hyperledger/cacti/security/dependabot/176
Weaknesses
CWE-248
CVE ID
CVE-2022-24434
GHSA ID
GHSA-wm7h-9275-46v2
Signed-off-by: Peter Somogyvari [email protected]
Pull Request Requirements
upstream/main
branch and squashed into single commit to help maintainers review it more efficient and to avoid spaghetti git commit graphs that obfuscate which commit did exactly what change, when and, why.-s
flag when usinggit commit
command. You may refer to this link for more information.Character Limit
A Must Read for Beginners
For rebasing and squashing, here's a must read guide for beginners.