codeceptjs / codeceptjs/CodeceptJS

Has high severity vulnerabilities

Offen
#4,864 3 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
stale
Vorherrschende Sprache
JavaScript
Sterne
4.2k
Forks
757
Ø Merge
2 T. 9 Std.
Gemergte PRs (30 T.)
16

Beschreibung

I installed CodeceptJS at latest, then Node.js showed it has vulnerabirities. I audited and the result is:

```
# npm audit report

cross-spawn <6.0.6
Severity: high
Regular Expression Denial of Service (ReDoS) in cross-spawn - https://github.com/advisories/GHSA-3xgq-45jj-v275
fix available via `npm audit fix --force`
Will install codeceptjs@3.5.9, which is a breaking change
node_modules/child-process-promise/node_modules/cross-spawn
child-process-promise >=2.2.0
Depends on vulnerable versions of cross-spawn
node_modules/child-process-promise
detox >=4.1.1
Depends on vulnerable versions of child-process-promise
node_modules/detox
@codeceptjs/detox-helper *
Depends on vulnerable versions of detox
node_modules/@codeceptjs/detox-helper
codeceptjs 2.2.1 || 3.5.1-2.beta.7 || >=3.5.10
Depends on vulnerable versions of @codeceptjs/detox-helper
node_modules/codeceptjs
```

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.