Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OSS: Override urllib version. #17013

Merged
merged 1 commit into from
Feb 12, 2025
Merged

OSS: Override urllib version. #17013

merged 1 commit into from
Feb 12, 2025

Conversation

sxn
Copy link
Contributor

@sxn sxn commented Feb 12, 2025

Description

ali-oss depends on a version of urllib which has a security vulnerability. There's been a PR opened in ali-oss' repo since May 2024, but it hasn't been merged.

This PR tells npm to use a newer version of urllib which does not have this vulnerability.

As I don't have an Aliyun OSS account / API key I was unable to test this change, but supposedly there aren't any breaking changes between the two versions of urllib.

Checklist

@sxn sxn requested a review from danielsequeira February 12, 2025 15:00
@raycastbot raycastbot added extension fix / improvement Label for PRs with extension's fix improvements extension: aliyun-oss Issues related to the aliyun-oss extension labels Feb 12, 2025
@raycastbot
Copy link
Collaborator

Thank you for your contribution! 🎉

🔔 @yangxyo you might want to have a look.

You can use this guide to learn how to check out the Pull Request locally in order to test it.

You can expect an initial review within five business days.

@danielsequeira danielsequeira merged commit 5d545bc into main Feb 12, 2025
11 checks passed
@danielsequeira danielsequeira deleted the override-urllib-aliyun branch February 12, 2025 15:04
Copy link
Contributor

Published to the Raycast Store:
https://raycast.com/yangxy/oss

@raycastbot
Copy link
Collaborator

🎉 🎉 🎉

We've rewarded your Raycast account with some credits. You will soon be able to exchange them for some swag.

sxn added a commit that referenced this pull request Feb 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
extension: aliyun-oss Issues related to the aliyun-oss extension extension fix / improvement Label for PRs with extension's fix improvements
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants