cleodora-forecasting / cleodora-forecasting/cleodora

Dependabot: Inefficient Regular Expression Complexity in nth-check

Open
#61 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
24
Forks
1
PR merge metrics
No merged PRs in 30d

Description

Dependabot cannot update nth-check to a non-vulnerable version

The latest possible version that can be installed is 1.0.2 because of the following conflicting dependencies:

react-scripts@5.0.1 requires nth-check@^1.0.2 via a transitive dependency on css-select@2.1.0
No patched version available for nth-check

The earliest fixed version is 2.0.1.

It might be a false positive: https://stackoverflow.com/questions/71282206/github-dependabot-alert-inefficient-regular-expression-complexity-in-nth-check

Contributor guide

Open the contributing guide

Research direction

Start by inspecting the dependency manifests and the react-scripts@5.0.1 dependency tree described in the issue, focusing on css-select@2.1.0 and nth-check. Determine whether the vulnerable dependency can be resolved or whether the alert is a false positive; done means the dependency is safely resolved or the alert's status is documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, react
Domain
frontend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.