Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Compiling fix for Vulnerable Regular Expression into updated list #525

Closed
wants to merge 1 commit into from
Closed

Conversation

PenguinOfWar
Copy link

As @magesh0819 mentioned in his comment on #510 this fixes the issue with the ReDoS vulnerable regex by rebuilding the dist files.

This package should be redeployed to npm after merge.

@tomasAlabes
Copy link

tomasAlabes commented Feb 2, 2021

@esamattis @stoeffel could you please merge this to fix the ReDos vulnerability?

@rustybailey
Copy link

@esamattis Is it possible for this to get merged? This is causing grunt to have an indirect vulnerability. See https://snyk.io/test/npm/grunt/1.4.0.

@adammy123
Copy link

@stoeffel can you help to merge this?

@esamattis
Copy link
Owner

3.3.6 is out with this.

@esamattis esamattis closed this Jan 23, 2022
@rustybailey
Copy link

@esamattis It looks like Snyk is reporting that this vulnerability still exists in 3.3.6: https://snyk.io/vuln/npm:underscore.string

@esamattis
Copy link
Owner

Hmph, wonder what's missing 🤔

@carneam
Copy link

carneam commented Jan 26, 2022

looks like Synk did update the latest update and it shows 3.3.6 does not have any vulnerabilities. Thanks Esa!

@rustybailey
Copy link

Thanks for confirming that @carneam. Looks like grunt 1.4.0 was also updated to have 0 vulnerabilities. See: https://snyk.io/vuln/npm:grunt.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants