Skip to content
This repository has been archived by the owner on Jul 24, 2024. It is now read-only.

Bump sass-graph@^4.0.1 #3292

Merged
merged 2 commits into from
Sep 8, 2022
Merged

Conversation

akhilgkrishnan
Copy link
Contributor

@akhilgkrishnan akhilgkrishnan commented Sep 1, 2022

Fixes #3293
reference: CVE-2022-25758

Regular expression denial of service in scss-tokenizer

@pitgrap
Copy link

pitgrap commented Sep 1, 2022

I thought this will remove the vulnerability, but it doesn't because it is added here without ^. 😥
@akhilgkrishnan, could you please change the dependency to to "sass-graph": "^4.0.1" to avoid manual updates for future releases?

@akhilgkrishnan
Copy link
Contributor Author

I thought this will remove the vulnerability, but it doesn't because it is added here without ^. 😥 @akhilgkrishnan, could you please change the dependency to to "sass-graph": "^4.0.1" to avoid manual updates for future releases?

Sure, @pitgrap I'll update that

Copy link

@pitgrap pitgrap left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@akhilgkrishnan
Copy link
Contributor Author

akhilgkrishnan commented Sep 1, 2022

@xzyfer, @nschonni Can you review this PR

@akhilgkrishnan akhilgkrishnan changed the title Bump sass-graph@4.0.1 Bump sass-graph@^4.0.1 Sep 2, 2022
@abelmark
Copy link

abelmark commented Sep 2, 2022

@xzyfer @nschonni any chance you could make this a priority? This is affecting a lot of enterprise users. Thank you!

@abelmark
Copy link

abelmark commented Sep 7, 2022

@xzyfer @nschonni bump

@xzyfer
Copy link
Contributor

xzyfer commented Sep 8, 2022

I'll try to cut a release tonight

@xzyfer xzyfer merged commit c716359 into sass:master Sep 8, 2022
@xzyfer
Copy link
Contributor

xzyfer commented Sep 8, 2022

v7.0.2 is published

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Bump sass-graph@4.0.1 or sass-graph@^4.0.1. Vulnerability in node-sass > sass-graph > scss-tokenizer
4 participants