max-mapper / max-mapper/extract-zip
Security Update: yauzl 3.2.1 (Dependabot run failed)
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 398
- Forks
- 144
- PR merge metrics
- No merged PRs in 30d
Description
Hi @maxogden,
The recent automated Dependabot run to update yauzl to version 3.2.1 failed due to a proxy error (GITHUB_REGISTRIES_PROXY).
Since yauzl 3.2.1 contains a critical security fix, could you please trigger a manual update or check the CI/CD pipeline?
Link to the failed run:
https://github.com/max-mapper/extract-zip/actions/runs/23084591562
Thanks for maintaining this project!
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the linked GitHub Actions run and inspect the failed Dependabot job, especially the GITHUB_REGISTRIES_PROXY error. Confirm how yauzl is declared and whether the update to 3.2.1 can complete; done means the dependency update succeeds through CI and the critical security fix is included.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, javascript
- Domain
- ci-cd, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100