-
-
Notifications
You must be signed in to change notification settings - Fork 20
Closed
Description
Package version
- 5.9.5
Node.js and npm version
- node: v16.14.0
- npm: v8.9.0
Sample Code (to reproduce the issue)
npm audit OR npm install
# npm audit report
glob-parent <5.1.2
Severity: high
glob-parent before 5.1.2 vulnerable to Regular Expression Denial of Service in enclosure regex - https://github.com/advisories/GHSA-ww39-953v-wcq6
No fix available
node_modules/globby/node_modules/glob-parent
fast-glob <=2.2.7
Depends on vulnerable versions of glob-parent
node_modules/globby/node_modules/fast-glob
globby 8.0.0 - 9.2.0
Depends on vulnerable versions of fast-glob
node_modules/globby
cpy 7.0.0 - 8.1.2
Depends on vulnerable versions of globby
node_modules/cpy
@adonisjs/assembler <=5.9.5
Depends on vulnerable versions of cpy
node_modules/@adonisjs/assembler
5 high severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.
Metadata
Metadata
Assignees
Labels
No labels