npm pack ignores root-level .gitignore & .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. --workspaces, --workspace=<name>). Anyone who has run npm pack or npm publish with workspaces, as of v7.9.0 & v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include.
npm (<code>v8.11.0</code> or greater), run: npm i -g npm@latestv8.11.0 version of npmnpm publish --dry-run or npm pack with an npm version >=7.9.0 & <8.11.0 inside the project's root directory using a workspace flag like: --workspaces or --workspace=<name> (ex. npm pack --workspace=foo)tar -tvf <package-on-disk> also works)npm deprecate <pkg>[@<version>] <message>)
3.3. Revoke or rotate any sensitive information (ex. passwords, tokens, secrets etc.) which might have been exposed
{
"severity": "HIGH",
"nvd_published_at": "2022-06-13T14:15:00Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-200"
],
"github_reviewed_at": "2022-06-02T15:37:27Z"
}