[Security]: linkify-it 5.0.0 in pnpm-lock.yaml is affected by ReDoS advisories (fixed in 5.0.2)
- Langage dominant
- Rust
- Étoiles
- 2.3k
- Forks
- 231
- Merge moyen
- 2 h 46 min
- PR mergées (30 j)
- 577
Description
Summary: pnpm-lock.yaml resolves linkify-it 5.0.0 (a markdown-it dependency), which is covered by the ReDoS advisories affecting the 5.0.x line below 5.0.2.
Area: Dependencies (Web UI)
Reproduction or evidence: `pnpm-lock.yaml` contains `linkify-it@5.0.0` reached through markdown-it's dependency graph; `pnpm audit` flags linkify-it < 5.0.2 for ReDoS. The override pins 5.0.2 and the regenerated lock resolves the patched release at the markdown-it consumption point.
Environment: BitFun version/commit 32f2427697ee16f253ee6119860a03255c0b3e47 (origin/main), pnpm 10.15.0.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Start with pnpm-lock.yaml and the dependency path through markdown-it; inspect the existing override and run pnpm audit using pnpm 10.15.0. Done means the regenerated lockfile resolves linkify-it at 5.0.2 or newer and the reported ReDoS advisory is no longer present.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- javascript
- Domaine
- security, web-dev
- Type d'issue
- Bug
- Difficulté
- 2/5
- Temps estimé
- 1-3 heures
- Activité
- Active
- Clarté
- Clairement spécifiée
- Accessibilité débutants
- 82/100