commitizen / commitizen/cz-cli

critical: ReDoS vulnerability from inquirer v8.2.0

未关闭
#883 1 条评论 10 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
JavaScript
星标
17.5k
派生
566
平均合并
8 小时 16 分钟
30 天内合并 PR
1

描述

Hi Team, there is a high vulnerability found in ansi-regex library for Regular Expression Denial of Service (ReDoS).
This library is used by inquirer v8.2.0.

Please increase the inquirer library to latest version. **Already a PR is open for that, please merge it as soon as possible:**
https://github.com/commitizen/cz-cli/pull/874

Refer the below urls to find more about vulnerability

https://snyk.io/advisor/npm-package/inquirer
https://snyk.io/vuln/npm:ansi-regex

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。