Download Latest Version security upgrade --deny-symlinks.zip (121.3 kB)
Email in envelope

Get an email when there's a new version of Harp

Home / v0.40.2
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2021-06-02 439 Bytes
security patch [Unauthorized File Access].tar.gz 2021-06-02 70.7 kB
security patch [Unauthorized File Access].zip 2021-06-02 121.4 kB
Totals: 3 Items   192.5 kB 0

Patch release that fixes unauthorized file access via encoded underscore.

Node Security Advisory https://www.npmjs.com/advisories/807

HackerOne Reprot https://hackerone.com/reports/453820

Detailed tests added in terraform@v1.20.1 https://github.com/sintaxi/terraform/commit/b1934873bba39427e3324a999b19b0741b04df0f

Basic harp test added... https://github.com/sintaxi/harp/commit/6547336e87096bd92e10aa0dedfe3b73b5f41a9f

Source: README.md, updated 2021-06-02