@pnpm/package-store@1007.0.0 vulnerabilities

A storage for packages

  • latest version

    1007.1.4

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    11 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @pnpm/package-store package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Resources Downloaded over Insecure Protocol

    @pnpm/package-store is an A storage for packages

    Affected versions of this package are vulnerable to Resources Downloaded over Insecure Protocol due to the absence of integrity hashes in the lockfile for HTTP or git-hosted tarball dependencies. An attacker can execute arbitrary code by serving different content from a remote server each time a dependency is installed, even when a lockfile is committed. This enables targeted or time-based attacks and can evade security audits by delivering benign code during review and malicious code at other times.

    Note: This is only exploitable if a package with an HTTP or git tarball dependency is installed as part of the dependency tree.

    How to fix Resources Downloaded over Insecure Protocol?

    Upgrade @pnpm/package-store to version 1007.1.0 or higher.

    <1007.1.0