Unverified Commit 60550330 authored by Sandro Jäckel's avatar Sandro Jäckel
Browse files

yarn2nix: fix "Incomplete URL substring sanitization"

'https://codeload.github.com' may be followed by an arbitrary host name.
parent a9c94419
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -46,7 +46,7 @@ async function fixPkgAddMissingSha1(pkg) {

  const [url, sha1] = pkg.resolved.split("#", 2);

  if (sha1 || url.startsWith("https://codeload.github.com")) {
  if (sha1 || url.startsWith("https://codeload.github.com/")) {
    return pkg;
  }