Skip to content

Removes event-stream package#26205

Merged
joelgriffith merged 7 commits intoelastic:masterfrom
joelgriffith:chore/remove-event-stream
Nov 28, 2018
Merged

Removes event-stream package#26205
joelgriffith merged 7 commits intoelastic:masterfrom
joelgriffith:chore/remove-event-stream

Conversation

@joelgriffith
Copy link
Contributor

Summary

Event-stream has some bad sub-dependencies covered in their current semver range (more here). Though we don't load this bad range, and given the nature of the comments on this issue, I would feel better if we didn't require this package anywhere. This PR does that.

Given that I'm not an expert in either of these area, I'd appreciate thorough review since it's outside of my current knowledge-base of Kibana.

Checklist

Use strikethroughs to remove checklist items you don't feel are applicable to this PR.

For maintainers

@elasticmachine
Copy link
Contributor

💔 Build Failed

@elasticmachine
Copy link
Contributor

💔 Build Failed

@guanghaofan
Copy link
Contributor

is this just the package related to this report?
Malicious code found in npm package event-stream downloaded 8 million times in the past 2.5 months

@kobelb
Copy link
Contributor

kobelb commented Nov 27, 2018

@guanghaofan yes, this is removing all usage of the problematic package. The backdoor that the package introduced doesn't affect Kibana, and the version which we're using doesn't have the backdoor, but given the current state of the matter, we determined it'd be safest to remove all usages.

@elasticmachine
Copy link
Contributor

💔 Build Failed

Copy link
Contributor

@spalger spalger left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@elasticmachine
Copy link
Contributor

💚 Build Succeeded

@joelgriffith
Copy link
Contributor Author

🎉 Thanks Spencer!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants