commitizen / commitizen/cz-cli
critical: ReDoS vulnerability from inquirer v8.2.0
未关闭
- 主要语言
- JavaScript
- 星标
- 17.5k
- 派生
- 566
- 平均合并
- 8 小时 16 分钟
- 30 天内合并 PR
- 1
描述
Hi Team, there is a high vulnerability found in ansi-regex library for Regular Expression Denial of Service (ReDoS).
This library is used by inquirer v8.2.0.
Please increase the inquirer library to latest version. **Already a PR is open for that, please merge it as soon as possible:**
https://github.com/commitizen/cz-cli/pull/874
Refer the below urls to find more about vulnerability
https://snyk.io/advisor/npm-package/inquirer
https://snyk.io/vuln/npm:ansi-regex
贡献指南
评估
这个 Issue 还没有评估数据。