andrewrk / andrewrk/node-mv

[Security] Update rimraf to 2.5.3

未关闭
#23 6 条评论 3 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
JavaScript
星标
156
派生
18
PR 合并指标
30 天内没有已合并 PR

描述

minimatch <=3.0.1 is vulnerable to a Regex Denial of Service attack
https://nodesecurity.io/advisories/118

node-mv depends on rimraf which depends on glob which depends on minimatch which has the vulnerability.

Please bump rimraf from ~2.4.0 to >=2.5.3 to resolve this vulnerability

https://github.com/isaacs/minimatch/commit/6944abf9e0694bd22fd9dad293faa40c2bc8a955
https://github.com/isaacs/node-glob/commit/f0f0872b660d83b1986cd1dd16ec4808fa183adc
https://github.com/isaacs/rimraf/commit/9e2c3102182f65bda76ca4051663784dd2db05e8

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。