Skip to content
This repository was archived by the owner on May 30, 2024. It is now read-only.

Conversation

@Nicholas-Arthur-Cook
Copy link
Contributor

@Nicholas-Arthur-Cook Nicholas-Arthur-Cook commented Aug 23, 2023

Requirements

  • I have added test coverage for new or changed functionality (Just a package bump, no changed functionality)
  • I have followed the repository's pull request submission guidelines
  • I have validated my changes against all supported platform versions

Related issues

CVE-2022-25883

Describe the solution you've provided

The security warning CVE-2022-25883 mentions that there was a ReDos through semver's Range function, which is not used in this codebase. However, having the old version causes security warnings for tools that use the launchdarkly-node-server-sdk npm package.

Describe alternatives you've considered

An alternative is waiting for the LaunchDarkly SDK team to update this themselves, or to open an issue to track this, but since it's a minor patch bump, I thought this was the most convenient way.

Additional context

n/a

@Nicholas-Arthur-Cook Nicholas-Arthur-Cook requested a review from a team August 23, 2023 18:08
@kinyoklion
Copy link
Member

Hello @Nicholas-Arthur-Cook,

Thank you for the contribution.

As an aside the most recent version of this pacakge is already using 7.5.4. Development has moved to: https://github.com/launchdarkly/js-core/tree/main/packages/sdk/server-node

And the package is now @launchdarkly/node-server-sdk.

Relevant package.json: https://github.com/launchdarkly/js-core/blob/36eb906e4cb77277b0d11ffb2488050c87b41026/packages/shared/sdk-server/package.json#L32C22-L32C22

The 7.x SDK has long term support, so bumping the minimum here will still be done.

It is worth noting that it isn't pinned to a minor, so an actual install will likely have a newer version, unless a package lock is forcing this version.

Thanks,
Ryan

@kinyoklion kinyoklion merged commit 18fde8c into launchdarkly:main Aug 23, 2023
LaunchDarklyReleaseBot added a commit that referenced this pull request Aug 23, 2023
## [7.0.3] - 2023-08-23 ### Changed: - Updated semver from `7.3.0` to `7.5.3`. (Thanks! [Nicholas-Arthur-Cook](#285)) --------- Co-authored-by: Eli Bishop <eli@launchdarkly.com> Co-authored-by: LaunchDarklyCI <dev@launchdarkly.com> Co-authored-by: Maxwell Gerber <maxwell.gerber@mulesoft.com> Co-authored-by: Chris West <solo-github@goeswhere.com> Co-authored-by: Ben Woskow <48036130+bwoskow-ld@users.noreply.github.com> Co-authored-by: Mike Zorn <mike@launchdarkly.com> Co-authored-by: Ben Woskow <bwoskow@launchdarkly.com> Co-authored-by: Robert J. Neal <rneal@launchdarkly.com> Co-authored-by: Ben Levy <benjaminlevy007@gmail.com> Co-authored-by: charukiewicz <christian@foxhound.systems> Co-authored-by: belevy <ben@foxhound.systems> Co-authored-by: charukiewicz <charukiewicz@protonmail.com> Co-authored-by: LaunchDarklyReleaseBot <launchdarklyreleasebot@launchdarkly.com> Co-authored-by: Ryan Lamb <4955475+kinyoklion@users.noreply.github.com> Co-authored-by: Ember Stevens <ember.stevens@launchdarkly.com> Co-authored-by: Ember Stevens <79482775+ember-stevens@users.noreply.github.com> Co-authored-by: Yusinto Ngadiman <yusinto@gmail.com> Co-authored-by: Louis Chan <lchan@launchdarkly.com> Co-authored-by: Louis Chan <91093020+louis-launchdarkly@users.noreply.github.com> Co-authored-by: ld-repository-standards[bot] <113625520+ld-repository-standards[bot]@users.noreply.github.com> Co-authored-by: Kane Parkinson <93555788+kparkinson-ld@users.noreply.github.com> Co-authored-by: Nicholas Cook <55813338+Nicholas-Arthur-Cook@users.noreply.github.com>
@kinyoklion
Copy link
Member

@Nicholas-Arthur-Cook Released in 7.0.3.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

2 participants