Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please update to minimatch 3.0.2 or higher to avoid a RegExp DoS issue #58

Closed
slinkardbrandon opened this issue Feb 25, 2019 · 3 comments

Comments

@slinkardbrandon
Copy link

Pending a fix from the open issue on a dependency of this project we'll need to update this repo to pull in their changes.

@zackdotcomputer
Copy link

I think this issue has been fixed by highlightjs version 9.15.6 moving the offending dependencies to devDependencies (see pull request here). Updating this package to depend on 9.15.6 or greater should fix the vulnerabilities being pulled in from their build system.

@felixfbecker
Copy link
Owner

Since highlight.js is a floating range, no update should be needed in this repo

@zackdotcomputer
Copy link

@felixfbecker Quite right, my mistake. I thought that package-lock.json would lock the version for downstream dependers but I was incorrect. I think this can be marked as closed, then.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants