GCWing / GCWing/OpenBitFun

[Security]: linkify-it 5.0.0 in pnpm-lock.yaml is affected by ReDoS advisories (fixed in 5.0.2)

オープン 初心者向け
#2,633 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Rust
スター
2.3k
フォーク
231
平均マージ
2時間 46分
マージ済み PR(30日)
577

説明

Summary: pnpm-lock.yaml resolves linkify-it 5.0.0 (a markdown-it dependency), which is covered by the ReDoS advisories affecting the 5.0.x line below 5.0.2.

Area: Dependencies (Web UI)

Reproduction or evidence: `pnpm-lock.yaml` contains `linkify-it@5.0.0` reached through markdown-it's dependency graph; `pnpm audit` flags linkify-it < 5.0.2 for ReDoS. The override pins 5.0.2 and the regenerated lock resolves the patched release at the markdown-it consumption point.

Environment: BitFun version/commit 32f2427697ee16f253ee6119860a03255c0b3e47 (origin/main), pnpm 10.15.0.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with pnpm-lock.yaml and the dependency path through markdown-it; inspect the existing override and run pnpm audit using pnpm 10.15.0. Done means the regenerated lockfile resolves linkify-it at 5.0.2 or newer and the reported ReDoS advisory is no longer present.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
javascript
領域
security, web-dev
issue の種類
バグ
難易度
2/5
見積もり時間
1〜3時間
活発さ
活発
明瞭さ
明確に書かれている
初心者へのやさしさ
82/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。