Skip to content
This repository was archived by the owner on Feb 7, 2026. It is now read-only.

fix: remove is package as dependency#1500

Merged
leahecole merged 4 commits intomainfrom
fix-sec-is-pkg
Jul 22, 2025
Merged

fix: remove is package as dependency#1500
leahecole merged 4 commits intomainfrom
fix-sec-is-pkg

Conversation

@alvarowolfx
Copy link
Contributor

Version 3.3.1 of the is package was compromised and published, containing some malware. The version was nucked from npm and an new v3.3.2 was published. Still we decided to remove it from the dependency chain, as it's easily replaceable.

Fixes #1498

@alvarowolfx alvarowolfx requested a review from a team July 21, 2025 21:19
@alvarowolfx alvarowolfx requested a review from a team as a code owner July 21, 2025 21:19
@alvarowolfx alvarowolfx requested a review from logachev July 21, 2025 21:19
@product-auto-label product-auto-label bot added size: m Pull request size is medium. api: bigquery Issues related to the googleapis/nodejs-bigquery API. labels Jul 21, 2025
@leahecole leahecole merged commit 926c9f8 into main Jul 22, 2025
19 of 20 checks passed
@leahecole leahecole deleted the fix-sec-is-pkg branch July 22, 2025 11:59
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

api: bigquery Issues related to the googleapis/nodejs-bigquery API. size: m Pull request size is medium.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remove dependency on is

2 participants