Skip to content

bump minimatch version#345

Open
Yavorss wants to merge 1 commit into
mysticatea:masterfrom
Yavorss:patch-1
Open

bump minimatch version#345
Yavorss wants to merge 1 commit into
mysticatea:masterfrom
Yavorss:patch-1

Conversation

@Yavorss

@Yavorss Yavorss commented Oct 26, 2022

Copy link
Copy Markdown

"A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service."
Affected versions: < 3.0.5

"A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service."
Affected versions: < 3.0.5
@beInDev

beInDev commented Feb 9, 2023

Copy link
Copy Markdown

+1 please

@samrat-ghosh-13

Copy link
Copy Markdown

+1

@voxpelli

Copy link
Copy Markdown

eslint-plugin-n is the maintained version of this module.

We switched to it in eg. eslint-config-standard / standard and it is maintained by me and other members of the official ESLint community organization.

Try that module out and if it isn't fixed there, then open a new PR in that project.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants