Added configuration to fix breaking change for latest node versions on windows cve-2024-27980 #131
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The issue lies here: https://nodejs.org/en/blog/vulnerability/april-2024-security-releases-2#command-injection-via-args-parameter-of-child_processspawn-without-shell-option-enabled-on-windows-cve-2024-27980---high
cve-2024-27980 requires any time a .bat or .cmd is run using the spawn or spawnSync commands it now needs to pass in a configuration of { shell: true }.
This prevented the npm install command from running on a Windows machine.
After applying the change, npm install runs to completion. I have also tested against the node.js package-lock.json version 20.11.1 and the addition of the configuration makes no noticeable difference.