max-mapper / max-mapper/extract-zip

Security Update: yauzl 3.2.1 (Dependabot run failed)

Open
#152 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
398
Forks
144
PR merge metrics
No merged PRs in 30d

Description

Hi @maxogden,

The recent automated Dependabot run to update yauzl to version 3.2.1 failed due to a proxy error (GITHUB_REGISTRIES_PROXY).

Since yauzl 3.2.1 contains a critical security fix, could you please trigger a manual update or check the CI/CD pipeline?

Link to the failed run:
https://github.com/max-mapper/extract-zip/actions/runs/23084591562

Thanks for maintaining this project!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the linked GitHub Actions run and inspect the failed Dependabot job, especially the GITHUB_REGISTRIES_PROXY error. Confirm how yauzl is declared and whether the update to 3.2.1 can complete; done means the dependency update succeeds through CI and the critical security fix is included.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, javascript
Domain
ci-cd, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.