[npm] fix to preserve all_versions metadata from the lockfile#5846
Merged
[npm] fix to preserve all_versions metadata from the lockfile#5846
Conversation
f66d8e2 to
30239b8
Compare
30239b8 to
1d6c772
Compare
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Minor follow up to #5801
In testing I saw that https://github.com/dsp-testing/npm-multiple-versions/ was still reporting the dependency was no longer vulnerable. It seems that in some cases when a dependency exists in both
package.jsonandpackage-lock.jsonwe weren't preserving all the versions. This turned out to be because when parsing dependencies frompackage-lock.jsonwe converted theDependencySetto a list of dependencies and back to aDependencySetwhich loses a bit of the version tracking state. Rather than try to preserve everything in the conversion I found it easier to just skip the unnecessary conversion.