Skip to content

Conversation

alvarowolfx
Copy link
Contributor

Version 3.3.1 of the is package was compromised and published, containing some malware. The version was nucked from npm and an new v3.3.2 was published. Still we decided to remove it from the dependency chain, as it's easily replaceable.

Fixes #1498

@alvarowolfx alvarowolfx requested review from a team as code owners July 21, 2025 21:19
@alvarowolfx alvarowolfx requested a review from logachev July 21, 2025 21:19
@product-auto-label product-auto-label bot added size: m Pull request size is medium. api: bigquery Issues related to the googleapis/nodejs-bigquery API. labels Jul 21, 2025
@leahecole leahecole merged commit 926c9f8 into main Jul 22, 2025
19 of 20 checks passed
@leahecole leahecole deleted the fix-sec-is-pkg branch July 22, 2025 11:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
api: bigquery Issues related to the googleapis/nodejs-bigquery API. size: m Pull request size is medium.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Remove dependency on is
2 participants