[Security] Update rimraf to 2.5.3
Đang mở
- Ngôn ngữ chính
- JavaScript
- Star
- 156
- Fork
- 18
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
minimatch <=3.0.1 is vulnerable to a Regex Denial of Service attack
https://nodesecurity.io/advisories/118
node-mv depends on rimraf which depends on glob which depends on minimatch which has the vulnerability.
Please bump rimraf from ~2.4.0 to >=2.5.3 to resolve this vulnerability
https://github.com/isaacs/minimatch/commit/6944abf9e0694bd22fd9dad293faa40c2bc8a955
https://github.com/isaacs/node-glob/commit/f0f0872b660d83b1986cd1dd16ec4808fa183adc
https://github.com/isaacs/rimraf/commit/9e2c3102182f65bda76ca4051663784dd2db05e8
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Đánh giá
Issue này chưa được đánh giá.