ant-design / ant-design/compatible
Upgrade Asyns-Validator to latest. ReDos vulnerability <4.0.4
Open
- Dominant language
- TypeScript
- Stars
- 93
- Forks
- 29
- PR merge metrics
- No merged PRs in 30d
Description
There's a new vulnerability with the async-validator version <4.0.4. Need to upgrade to latest
https://security.snyk.io/vuln/SNYK-JS-ASYNCVALIDATOR-2311201
Contributor guide
No contributing guide indexed for this repository
Research direction
Locate the dependency declaration for async-validator and review the linked Snyk advisory first. Update the dependency to a version that addresses the reported vulnerability, then run the repository's existing checks to confirm the upgrade does not break compatibility.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100