Skip to content

Dependency Security: js-beautify pulls vulnerable minimatch (ReDoS) #110

Description

@Razerspine

Hello! I'm using pug-plugin@6.0.0 in a monorepo. Currently, js-beautify depends on older versions of glob and editorconfig, which in turn pull minimatch < 10. This triggers a ReDoS vulnerability advisory.

To fix this, I have to use manual overrides in package.json to force minimatch@10 and glob@13.

Are there any plans to update the js-beautify dependency or switch to a more secure formatter (like Prettier) to resolve this transitive vulnerability?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions