Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update braces to 2.3.1 #684

Closed
wants to merge 1 commit into from
Closed

Update braces to 2.3.1 #684

wants to merge 1 commit into from

Conversation

maxcbc
Copy link

@maxcbc maxcbc commented Feb 21, 2018

Update braces to 2.3.1

Braces has 2.3.0 has a ReDos vulnerability: https://snyk.io/vuln/npm:braces:20180219
This is fixed 2.3.1.

Braces has 2.3.0 has a ReDos vulnerability: https://snyk.io/vuln/npm:braces:20180219
This is fixed in 2.3.1.
@coveralls
Copy link

coveralls commented Feb 21, 2018

Coverage Status

Coverage remained the same at 98.498% when pulling 987d5b5 on maxcbc:bump_braces_to_2.3.1 into a95a1f8 on paulmillr:master.

@es128
Copy link
Contributor

es128 commented Feb 21, 2018

This is unnecessary. The fix is covered in the semver range, and chokidar is used in locally-run build tools where I'm not very concerned about users trying to ReDos themselves.

@es128 es128 closed this Feb 21, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants