Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CVE-2024-4068] Uncontrolled resource consumption found in braces (non-issue, see comments) #2203

Closed
promaldowski15 opened this issue May 14, 2024 · 3 comments

Comments

@promaldowski15
Copy link

Snyk reported a vulnerability in the nodemon 3.1.0 dependency.

Issues with no direct upgrade or patch:
11:08:29 ✗ Uncontrolled resource consumption [High Severity][https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727] in braces@3.0.2
11:08:29 introduced by nodemon@3.1.0 > chokidar@3.5.3 > braces@3.0.2
11:08:29 No upgrade or patch available

https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727

@remy
Copy link
Owner

remy commented May 19, 2024

See here for details (and frankly I fully support this stand):

paulmillr/chokidar#1314

Going to lock, edit and keep open.

@remy remy changed the title [CVE-2024-4068] Uncontrolled resource consumption found in braces [CVE-2024-4068] Uncontrolled resource consumption found in braces (non-issue, see comments) May 19, 2024
@remy
Copy link
Owner

remy commented May 19, 2024

I'll close once it's closed off, or dies, upstream.

Repository owner locked as resolved and limited conversation to collaborators May 19, 2024
@remy
Copy link
Owner

remy commented May 29, 2024

Closing (unplanned/non-issue) - again, you can follow conversations upstream.

@remy remy closed this as completed May 29, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants