Skip to content

Conversation

Mugunthan-Ramalingam
Copy link
Contributor

@Mugunthan-Ramalingam Mugunthan-Ramalingam commented May 9, 2024

Description

The dependabot alerts the following issues which expose the pubspec.lock file in the GitHub public repository.

  • The issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
  • The issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.

So, we removed the pubspec.lock file to avoid vulnerability to the repository.

Copy link
Collaborator

@Yuvaraj-Gajaraj Yuvaraj-Gajaraj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fine

@Mugunthan-Ramalingam Mugunthan-Ramalingam changed the title FLUT-885029 - [Others] Removed pub spec file FLUT-885029 - [Others] Removed pubspec.lock file because of dependabot issue. May 14, 2024
@Mugunthan-Ramalingam Mugunthan-Ramalingam changed the title FLUT-885029 - [Others] Removed pubspec.lock file because of dependabot issue. FLUT-885029 - [Others] Removed pubspec.lock file because of dependabot issue May 14, 2024
@VijayakumarMariappan VijayakumarMariappan merged commit 206cb05 into SyncfusionExamples:master May 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants