Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6068 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm. |
Github GHSA |
GHSA-hj9c-8jmm-8c52 | Packing does not respect root-level ignore files in workspaces |
Thu, 24 Apr 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T16:23:31.058Z
Reserved: 2022-04-13T00:00:00.000Z
Link: CVE-2022-29244
Updated: 2024-08-03T06:17:54.265Z
Status : Modified
Published: 2022-06-13T14:15:09.027
Modified: 2025-04-23T17:15:46.060
Link: CVE-2022-29244
OpenCVE Enrichment
No data.
EUVD
Github GHSA