Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Dependencies have security vulnerabilities in inflight #3209

Closed
HalaburdaAndrei opened this issue Feb 7, 2025 · 3 comments
Closed

Dependencies have security vulnerabilities in inflight #3209

HalaburdaAndrei opened this issue Feb 7, 2025 · 3 comments
Labels
more information required Issue requires more information or a response from the customer

Comments

@HalaburdaAndrei
Copy link

HalaburdaAndrei commented Feb 7, 2025

Note
For @salesforce/cli even the latest 2.75.5 version

Summary

Hello @Salesforce/CLI team. We scanned @Salesforce/CLI source code with Snyk
Missing Release of Resource after Effective Lifetime [Medium Severity][https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116] in inflight@1.0.6
introduced by @salesforce/cli@2.75.5 > @salesforce/plugin-trust@3.7.59 > shelljs@0.8.5 > glob@7.2.3 > inflight@1.0.6 and 5 other path(s)

This library is not maintained, and currently, there is no fix for this issue. To overcome this vulnerability, several dependent packages have eliminated the use of this library. Will there be an opportunity to fix this?

@HalaburdaAndrei HalaburdaAndrei added the investigating We're actively investigating this issue label Feb 7, 2025
Copy link

github-actions bot commented Feb 7, 2025

Thank you for filing this issue. We appreciate your feedback and will review the issue as soon as possible. Remember, however, that GitHub isn't a mechanism for receiving support under any agreement or SLA. If you require immediate assistance, contact Salesforce Customer Support.

Copy link

github-actions bot commented Feb 7, 2025

Hello @HalaburdaAndrei 👋 It looks like you didn't include the full Salesforce CLI version information in your issue.
Please provide the output of version --verbose --json for the CLI you're using (sf or sfdx).

A few more things to check:

  • Make sure you've provided detailed steps to reproduce your issue.
    • A repository that clearly demonstrates the bug is ideal.
  • Make sure you've installed the latest version of Salesforce CLI. (docs)
    • Better yet, try the rc or nightly versions. (docs)
  • Try running the doctor command to diagnose common issues.
  • Search GitHub for existing related issues.

Thank you!

@github-actions github-actions bot added more information required Issue requires more information or a response from the customer and removed investigating We're actively investigating this issue labels Feb 7, 2025
@cristiand391
Copy link
Member

shelljs doesn't seem to be really affected by this, see: shelljs/shelljs#1149 (comment)

@cristiand391 cristiand391 closed this as not planned Won't fix, can't repro, duplicate, stale Feb 7, 2025
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
more information required Issue requires more information or a response from the customer
Projects
None yet
Development

No branches or pull requests

2 participants