This repository was archived by the owner on May 1, 2024. It is now read-only.
prism-jest package was removed by 8pm security team few years back but there is no mention of what exactly was present in the package that caused its removal #1103
Closed
thisisashwani
started this conversation in
General
Replies: 1 comment
-
We can't share information beyond what's already public. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I happened to land on a package named
prism-jest
in our of my codebases while doing a node version upgrade. On an accidental search, I realised thatprism-jest
had a severe vulnerability as per Github security advisory - GHSA-mj5j-3f4h-8rmp. I also see that this package was removed by npm security team because of the same - https://www.jsdelivr.com/package/npm/prism-jest.So, I went ahead to this particular package present in my
node_modules
and tried to understand what exactly can be causing such a severe issue. It's a simple package with few lines of code. So, I am very curious to know what exactly was in the code that led to its removal. I have tried to search quite a bit on net regarding this, but there has not been anything I could find other than those two links.I am not sure how to reach out to rpm security team for this, so starting here with this discussion.
Beta Was this translation helpful? Give feedback.
All reactions