Skip to content

Publish New NPM version for Node-Static聽#231

Description

@NEllusion

Hey 馃憢 I notice its been a while since a new version of node-static has been pushed to NPM, and the version that currently exists there contains the package minimist which has a (github advisory) for it. This package was being used which is used by a package in this project called optimist. In this pull request, @brettz9 removed optimist to resolve this vulnerability. As a result, publishing a new version of node-static will ensure that all users of this package will use a safe version by default.

cc @cloudhead

Activity

  1. ibesty commented on Jan 16, 2022

    @ibesty

    Can anyone publish the latest updates to npm? I see that the latest commit fixes some issues but doesn't publish to npm

  2. brettz9 commented on Jan 17, 2022

    @brettz9
    Collaborator

    @cloudhead : I went ahead and replaced the history so as to avoid all the merges (though keeping a copy of the old branch with all of them), so I think it should be ready for your review before a release. (And if accepted, we can also close #232 )

  3. brettz9 commented on Feb 11, 2022

    @brettz9
    Collaborator

    @cloudhead : Can we go ahead with this?

  4. brettz9 commented on Mar 9, 2022

    @brettz9
    Collaborator

    @cloudhead : Do you want periodic checkbacks like this or do you have an ETA? The commit history should be all cleaned up.

  5. kenjura commented on Mar 31, 2022

    @kenjura

    Am I crazy, or did this replace the npm package with the wrong code?

    • using ubuntu 20.04.2 LTS (WSL)
    • npm i node-static
    • observe: package.json and package-lock.json shows 0.7.11
    • more node_modules/bin/node-static/lib/node-static.js
    • observe: line 11 reads var version = [0, 7, 9];
    • observe: missing features, "var"s everywhere, code completely does not match github

    image

    Maybe I'm losing it, but something is pretty bizarre here, and my only theory is a funky npm registry update.

    alternate path to reproduce:

    edit:

    • npm i cloudhead/node-static installs the correct version
  6. brettz9 commented on Mar 31, 2022

    @brettz9
    Collaborator

    If you look at https://www.npmjs.com/package/node-static , it was last published 4 years ago, and the latest version is 0.7.11.

    If you use the "blame" feature for the file defining the version, you can see a commit from 12 months ago where it was changed from var to const (but still listing 0.7.9) at the time.

    Thus, the version just hadn't been updated despite subsequent releases up to 0.7.11

    As to why there is a const, etc., there have been (many) changes on master since that time and we are awaiting a new publishing. The project owner still needs to give final approval on these changes, so these many changes have not been published to npm yet.

    FWIW, some of the changes are available on my fork, @brettz9/node-static (using a different (smaller) versioning number as it is an independent project), but as the author of the regular node-static here eventually replied granting access to the project with openness to including my changes, I resumed work here.

  7. andreeatirgovatustockX commented on Sep 7, 2022

    @andreeatirgovatustockX

    Hi. When this upgrade will be done? We get this issue from snyk

    Denial of Service (DoS) [High Severity][https://snyk.io/vuln/SNYK-JS-NODESTATIC-1297183] in node-static@0.7.11
        introduced by node-static@0.7.11
      No upgrade or patch available
    

    Thank you.

  8. cloudhead commented on Sep 14, 2022

    @cloudhead
    Owner

    Hey, sorry, am pretty overwhelmed with other stuff, @brettz9 -- can you point me again to the cleaned up history?

  9. brettz9 commented on Sep 15, 2022

    @brettz9
    Collaborator

    Sure, @cloudhead ...Thankfully, we were able to get the history cleaned, so master is already a cleaned history.

    If you want the diffs from what is apparently the final commit for the latest published published version, 0.7.11 (there's no tag for it), see https://github.com/cloudhead/node-static/compare/e59fe21dffbee46678362d26d26fdfb241f49506..master , but there's a whole lot of noise if trying to look at all at once.

  10. francoisihry commented on Sep 15, 2022

    @francoisihry

    Hi,
    We are concerned by the same issue as @andreeatirgovatustockX .
    Is there a workaround we can apply to not be impacted by the SNYK-JS-NODESTATIC-1297183 security issue anymore ?
    (waiting until a new version is published)

  11. brettz9 commented on Sep 15, 2022

    @brettz9
    Collaborator

    @francoisihry : As mentioned at https://security.snyk.io/vuln/SNYK-JS-NODESTATIC-1297183 , this was fixed in master of this project. Ideally, however, @cloudhead may be able to review the commits on master since the last release so a new npm release can be published.

  12. francoisihry commented on Sep 27, 2022

    @francoisihry

    Thank you @brettz9 we look forward for a new version to be released so that we can easily integrate the fix.

  13. peterbernhardt commented on Oct 16, 2025

    @peterbernhardt

    Following up on #244
    @brettz9 when can we expect a new release?

  14. brettz9 commented on Oct 16, 2025

    @brettz9
    Collaborator

    Not having heard back from @cloudhead , on August 14, I filed for a transfer of ownership to GitHub (who now manage npm). They are unfortunately unable to give a wait time.

    If it appears it is taking too long, I've reserved a "node-static" organization, and can publish a @node-static/node-static fork.

  15. brettz9 commented on Oct 30, 2025

    @brettz9
    Collaborator

    Ok, I've gotten around to publishing the fork of @node-static/node-static . Feel free to add further issues to its repository at https://github.com/node-static/node-static . I can keep this issue open here to indicate the fact of the change, and in case we hear back from anyone who may decide to grant access.

  16. tamird commented on Dec 1, 2025

    @tamird

    Ok, I've gotten around to publishing the fork of @node-static/node-static . Feel free to add further issues to its repository at https://github.com/node-static/node-static . I can keep this issue open here to indicate the fact of the change, and in case we hear back from anyone who may decide to grant access.

    This seems to be a dead link. What's up?

  17. brettz9 commented on Dec 1, 2025

    @brettz9
    Collaborator

    Ok, I've gotten around to publishing the fork of @node-static/node-static . Feel free to add further issues to its repository at https://github.com/node-static/node-static . I can keep this issue open here to indicate the fact of the change, and in case we hear back from anyone who may decide to grant access.

    This seems to be a dead link. What's up?

    Whoops. I created it private. Now switched to public. The npm package has been available for some time though.

  18. brettz9 commented on Jan 26, 2026

    @brettz9
    Collaborator

    As far as ownership of node-static I received a message from GitHub today stating:

    We are sunsetting the previous policy that allowed users to dispute namespace ownership. Moving forward, all requests will need to be submitted as Trademark Policy Violation Reports through [Github's Trademark Policy](https://docs.github.com/en/site-policy/content-removal-policies/github-trademark-policy).
     
    As a result, your existing dispute request will be closed. If you would like to pursue your claim, please submit a new request via our online form:
     
    https://support.github.com/contact/trademark-policy
    

    Since I do not hold any trademark for the name, it seems to me that we may need to be content with @node-static/node-static.

    EDIT: I confirmed at the form that indicating I am not the trademark holder gives the following message:

    We are unable to process Trademark Policy Violation Notices unless they are submitted by the trademark holder or an agent authorized to act on their behalf.

  19. Zarel commented on Oct 5, 2026

    @Zarel

    Hi, @brettz9. I'm glad you've migrated to node-static/node-static.

    I notice the npm package is still 8 years without an updated version. I believe you can dispute ownership at NPM, too (I've done that in the past), and I recommend that for node-static.

    I'd also recommend pushing a README update here, pointing users to the new repository.

  20. brettz9 commented on Oct 5, 2026

    @brettz9
    Collaborator

    Hi, @brettz9. I'm glad you've migrated to node-static/node-static.

    I notice the npm package is still 8 years without an updated version. I believe you can dispute ownership at NPM, too (I've done that in the past), and I recommend that for node-static.

    With GitHub being the new owners of npm, their reply about sunsetting their old policy allowing for such claims has been revoked. It is only allowed now for trademark violations.

    I'd also recommend pushing a README update here, pointing users to the new repository.

    Good idea. I've added such a note indicating the current status of the project with a link to the fork. (I wouldn't do this if the owner were objecting to my fork, but it just seems they are not available.)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions