Skip to content
This repository has been archived by the owner on May 6, 2024. It is now read-only.

ReDoS security issues that may require Nuxt v3 upgrade #422

Closed
16 tasks
wesley-dean-gsa opened this issue May 12, 2022 · 0 comments
Closed
16 tasks

ReDoS security issues that may require Nuxt v3 upgrade #422

wesley-dean-gsa opened this issue May 12, 2022 · 0 comments

Comments

@wesley-dean-gsa
Copy link
Contributor

wesley-dean-gsa commented May 12, 2022

User Story

As a BEARS security engineer, in order to address outstanding ReDoS security findings, I would like update our dependencies to incorporate ReDoS-resistant tooling .

Security findings 6 (css-what) and 10 (glob-parent) relate to our use of Nuxt v2.15.8. These findings are both considered "moderate" and relate to "ReDoS" (Regular Expression Denial of Service) vulnerabilities.

Unfortunately, 2.15.8, released on August 11, 2021, is the current release. The most recent commit to the default branch was on December 17, 2021.

It appears that nuxt v2 isn't receiving active development. Issue #9284 was created when the issue was discovered. It seems like attention is being focused on v3 and the v2 => v3 bridge projects.

For what it's worth, a release candidate of v3 is currently (May, 2022) available. That said, v2 => v3 is a major release and, by semantic versioning standards, involves changes that are not backwards-compatible. It's entirely possible that we'll need to rewrite some code to go from v2 to v3.

Pre-conditions:

  • a version of Nuxt is available that address concerns with css-what and glob-parent

Acceptance Criteria:

Definition of Done:

  • Code complete
  • Tests coverage is greater than team benchmark (90% goal)
  • Security scans passed
  • Acceptance Criteria is met and it works as expected
  • Accessibility tested
  • Build process and deployment is automated and repeatable
  • Load testing/performance testing
  • Self Documentation whenever possible
  • Feature toggles if appropriate
  • Deployed to staging
  • Usability testing
  • PR approved / Peer reviewed
  • PO approved
@wesley-dean-gsa wesley-dean-gsa added this to Product Backlog in 10x BEARS - Phase 4 via automation May 12, 2022
10x BEARS - Phase 4 automation moved this from Product Backlog to Done Feb 3, 2023
@FatmaBakir FatmaBakir reopened this Feb 3, 2023
10x BEARS - Phase 4 automation moved this from Done to Product Backlog Feb 3, 2023
10x BEARS - Phase 4 automation moved this from Product Backlog to Done Jan 30, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
Development

No branches or pull requests

3 participants