Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix vulnerability in semver:6.3.0 #30

Closed
ofrolenko opened this issue Jun 29, 2023 · 1 comment
Closed

Fix vulnerability in semver:6.3.0 #30

ofrolenko opened this issue Jun 29, 2023 · 1 comment

Comments

@ofrolenko
Copy link

semver <7.5.2
Severity: moderate
semver vulnerable to Regular Expression Denial of Service - GHSA-c2qf-rxjj-qqgw
No fix available

├─┬ stylelint@15.9.0
│ └─┬ meow@9.0.0
│ └─┬ read-pkg-up@7.0.1
│ └─┬ read-pkg@5.2.0
│ └─┬ normalize-package-data@2.5.0
│ └── semver@5.7.1 deduped

normalize-package-data: 5.0.0 package has semver:7.3.5 (and I can update it to version 7.5.2 with fix), but I can't update it for read-pkg because it doesn't allow update a major version. Could you update normalize-package-data to version 5.. in your project?

@sindresorhus
Copy link
Owner

The latest version of this package already uses normalize-package-data@5. I don't have any plans to update older versions.

@sindresorhus sindresorhus closed this as not planned Won't fix, can't repro, duplicate, stale Jun 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants