commitizen / commitizen/cz-cli
critical: ReDoS vulnerability from inquirer v8.2.0
Đang mở
- Ngôn ngữ chính
- JavaScript
- Star
- 17.5k
- Fork
- 566
- Merge trung bình
- 8 giờ 16 phút
- Pull request đã merge (30 ngày)
- 1
Mô tả
Hi Team, there is a high vulnerability found in ansi-regex library for Regular Expression Denial of Service (ReDoS).
This library is used by inquirer v8.2.0.
Please increase the inquirer library to latest version. **Already a PR is open for that, please merge it as soon as possible:**
https://github.com/commitizen/cz-cli/pull/874
Refer the below urls to find more about vulnerability
https://snyk.io/advisor/npm-package/inquirer
https://snyk.io/vuln/npm:ansi-regex
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.