All @azure/ms-rest-nodeauth versions

@azure/ms-rest-nodeauth @2.0.2

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
43
Risk Score
MIT
License
No
Install Scripts
3
Dependencies
16
Dev Dependencies
64.4 KB
Package Size
Published

Azure Authentication library in node.js with type definitions.

Maintainers

amarzaveryazure-sdkbillytrendsergeyshandarveronicaggvladbarosan

Keywords

nodeazureautorestauthenticationenvironmentadal

Dependencies (3)

PackageConstraintRegistry Status
adal-node ^0.1.28 No greenflagged match
@azure/ms-rest-js ^1.8.7 auto_approved
@azure/ms-rest-azure-env ^1.1.2 auto_approved

Dev Dependencies (16)

PackageConstraintRegistry Status
nyc ^14.1.0 auto_approved
chai ^4.2.0 auto_approved
nock ^10.0.1 No greenflagged match
mocha ^5.2.0 auto_approved
dotenv ^8.0.0 auto_approved
rollup ^0.67.1 auto_approved
tslint ^5.11.0 auto_approved
ts-node ^7.0.1 No greenflagged match
typescript ^3.1.3 auto_approved
@types/chai ^4.1.6 auto_approved
@types/node ^10.12.0 auto_approved
npm-run-all ^4.1.3 auto_approved
@types/mocha ^5.2.5 auto_approved
@types/dotenv ^6.1.1 No greenflagged match
rollup-plugin-sourcemaps ^0.4.2 No greenflagged match
@ts-common/azure-js-dev-tools ^0.4.9 Not imported

Transitive Dependency Tree

41 transitive deps max depth 7
  ├─ @azure/ms-rest-azure-env ^1.1.2 → 1.1.2
  ├─ @azure/ms-rest-js ^1.8.7 → 1.11.2
├─ adal-node ^0.1.28
  ├─ @azure/core-auth ^1.1.4 → 1.10.1
  ├─ axios ^0.21.1
  ├─ form-data ^2.3.2 → 2.5.5
  ├─ tough-cookie ^2.4.3
  ├─ tslib ^1.9.2 → 1.14.1
  ├─ tunnel 0.0.6 → 0.0.6
  ├─ uuid ^3.2.1 → 3.4.0
├─ xml2js ^0.4.19
  ├─ @azure/abort-controller ^2.1.2 → 2.1.2
  ├─ @azure/core-util ^1.13.0 → 1.13.1
  ├─ asynckit ^0.4.0
  ├─ combined-stream ^1.0.8 → 1.0.8
  ├─ es-set-tostringtag ^2.1.0 → 2.1.0
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ mime-types ^2.1.35 → 2.1.35
  ├─ safe-buffer ^5.2.1 → 5.2.1
├─ tslib ^2.6.2 → 2.8.1
  ├─ @azure/abort-controller ^2.1.2 → 2.1.2
  ├─ @typespec/ts-http-runtime ^0.3.0 → 0.3.5
  ├─ delayed-stream ~1.0.0 → 1.0.0
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ get-intrinsic ^1.2.6 → 1.3.1
  ├─ has-tostringtag ^1.0.2 → 1.0.2
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ mime-db 1.52.0
├─ tslib ^2.6.2 → 2.8.1
  ├─ async-function ^1.0.0
  ├─ async-generator-function ^1.0.0 → 1.0.0
  ├─ call-bind-apply-helpers ^1.0.2 → 1.0.2
  ├─ es-define-property ^1.0.1 → 1.0.1
  ├─ es-errors ^1.3.0 → 1.3.0
  ├─ es-object-atoms ^1.1.1 → 1.1.2
  ├─ function-bind ^1.1.2 → 1.1.2
  ├─ generator-function ^2.0.0 → 2.0.1
  ├─ get-proto ^1.0.1
  ├─ gopd ^1.2.0 → 1.2.0
  ├─ has-symbols ^1.1.0 → 1.1.0
  ├─ has-symbols ^1.0.3 → 1.1.0
  ├─ hasown ^2.0.2 → 2.0.4
  ├─ http-proxy-agent ^7.0.0 → 7.0.2
  ├─ https-proxy-agent ^7.0.0 → 7.0.6
  ├─ math-intrinsics ^1.1.0 → 1.1.0
├─ tslib ^2.6.2 → 2.8.1
  ├─ agent-base ^7.1.2 → 7.1.4
  ├─ agent-base ^7.1.0 → 7.1.4
  ├─ debug ^4.3.4 → 4.4.3
  ├─ debug 4 → 4.4.3
  ├─ es-errors ^1.3.0 → 1.3.0
├─ function-bind ^1.1.2 → 1.1.2
  ├─ ms ^2.1.3 → 2.1.3

Changes from v1.1.1

Dependency Changes

ChangePackageVersion
changed @azure/ms-rest-js ^1.8.6 → ^1.8.7

File Changes

0 added 0 removed 34 modified size delta: +13.7 KB

Risk Dispositions (1 applicable to this version, 0 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
osv:GHSA-qpfw-4m9x-rxx8 osv reject AI AI (osv): EoP vulnerability affects all versions < 3.0.8; any version in that range should be rejected in favor of the patched release.

SAST Findings (2)

CRITICAL GHSA-qpfw-4m9x-rxx8: Improper Privilege Management in Azure ms-rest-nodeauth osv

[Always reject] CVSS 7.8 (HIGH) — CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 43. Findings: 1 critical (+40), 1 low (+3), 8 info (+0).

Published to npm: