-
Notifications
You must be signed in to change notification settings - Fork 195
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: node-ipc #181
fix: node-ipc #181
Conversation
LGTM |
This comment was marked as off-topic.
This comment was marked as off-topic.
🎉 This PR is included in version 1.70.6 🎉 The release is available on: Your semantic-release bot 📦🚀 |
有鉴于此模块的有意行为(包括更恶劣的根据IP覆盖文件),光针对特定版本可能还不够,可能需要暂时直接锁定后续所有版本。 |
我会先锁定 node-ipc 的更新同步 |
@fengmk2 是不是顺便把这 3 个版本先手动删掉?避免用 npm/yarn/pnpm 连 npmmirrror 的用户受到影响。 新版 cnpm registry 好像没有迁移这个:cnpm/cnpmcore#184 |
Copy from vuejs/vue-cli#7054 (comment) The behavior — committed malicious code, deleted comments which expose such code, revoked the api key after been exposed and promoted the sophistry that the code not work because api key is not valid — make me think the guy is not worth trust anymore. I strongly suggest npmmirror not only blacklist node-ipc but all his packages. |
好吓人啊 |
https://github.com/RIAEvangelist/node-ipc/issues/233