Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

package dependency scss-tokenizer flaged unsafe #118

Closed
vycos-zen opened this issue Jul 14, 2022 · 7 comments · Fixed by #119
Closed

package dependency scss-tokenizer flaged unsafe #118

vycos-zen opened this issue Jul 14, 2022 · 7 comments · Fixed by #119

Comments

@vycos-zen
Copy link

vycos-zen commented Jul 14, 2022

reference: CVE-2022-25758

Regular expression denial of service in scss-tokenizer

symptom: yarn.lock indicates a dependency to scss-tokenizer: ^0.3.0, trigering a dependabot warning

Severity
High
7.5/ 10

scss-tokenizer current version is 0.4.2

impacted packages

expected outcome: no safety warning to the package.

is it possible to update this package?

@SmolinPavel
Copy link

Yeah, this vulnerability has been promoted from moderate to high, so looks like it should be addressed.

@paulrrogers
Copy link

This scss-tokenizer fork claims to have a fix. 🤞 it will be accepted upstream.

@mporkola
Copy link

It was merged, now we just need update the dependency version in sass-graph. @xzyfer would you be able to do it, pretty please? 🙏

@github-sj
Copy link

Can somebody please provide an ETA on when this can be done?

@xzyfer
Copy link
Owner

xzyfer commented Sep 1, 2022

Fixed in v4.0.1

@github-sj
Copy link

Fixed in v4.0.1

Thank you very much.

@vycos-zen
Copy link
Author

sweet! thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

6 participants