Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update fileset dependency per https://nodesecurity.io/advisories/118 #653

Closed
ntwb opened this issue Jun 24, 2016 · 8 comments
Closed

Update fileset dependency per https://nodesecurity.io/advisories/118 #653

ntwb opened this issue Jun 24, 2016 · 8 comments

Comments

@ntwb
Copy link

ntwb commented Jun 24, 2016

The minimatch NPM module has been patched due to a regular expression denial of service:

Once this is merged and a new release of fileset is released then a pull request can be created

@ntwb
Copy link
Author

ntwb commented Jun 27, 2016

Fileset 2.0.2 has now been released with this minimatch dependency update:

mklabs/node-fileset@v1.0.1...v2.0.2

@use-strict
Copy link

Any updates here?

@ghost
Copy link

ghost commented Jul 13, 2016

Hi, is there any news on this?

@austinnichols101
Copy link

Bump.

@gotwarlost
Copy link
Owner

I've not had time to take a look and it is not a simple update since one of the tests fail and I need to figure out why. Will get to it soon,

@popomore
Copy link
Contributor

popomore commented Jul 28, 2016

fileset has always ignored node_modules mklabs/node-fileset@c6593c0

So this testcase failed.

@jonfreedman
Copy link

+1

@maxkoryukov
Copy link

Looks, like there is an overall solution: #673

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants