Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[deps] Bump up local instance of semver package due to GHSA-c2qf-rxjj-qqgw #283

Conversation

alexander-smolyakov
Copy link
Contributor

Description:

Security scanners alerted that the nvs tool contains a vulnerable version of the semver package.

The nvs contains a local instance of the smever v5.4.1 in the deps folder. This version is vulnerable to Regular Expression Denial of Service (ReDoS). According to the GitHub Advisory, updating the package to version 5.7.2 should remediate the vulnerability.

Link to related semver release: https://github.com/npm/node-semver/releases/tag/v5.7.2

Changelog:

  • The semver package updated to v5.7.2 (5.4.1 -> 5.7.2)

- Bump up the local instance of the semver package to v.5.7.2 to remediate GHSA-c2qf-rxjj-qqgw
@alexander-smolyakov
Copy link
Contributor Author

Hey @jasongin, could you please take a look at this PR?

@jasongin jasongin merged commit 5960750 into jasongin:master Aug 16, 2023
3 checks passed
@alexander-smolyakov alexander-smolyakov deleted the bump-semver-due_to_GHSA-c2qf-rxjj-qqgw branch August 17, 2023 08:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants