commitizen / commitizen/cz-cli
critical: ReDoS vulnerability from inquirer v8.2.0
未關閉
- 主要語言
- JavaScript
- 星號
- 17.5k
- 分支
- 566
- 平均合併
- 8 小時 16 分鐘
- 30 天內合併 PR
- 1
描述
Hi Team, there is a high vulnerability found in ansi-regex library for Regular Expression Denial of Service (ReDoS).
This library is used by inquirer v8.2.0.
Please increase the inquirer library to latest version. **Already a PR is open for that, please merge it as soon as possible:**
https://github.com/commitizen/cz-cli/pull/874
Refer the below urls to find more about vulnerability
https://snyk.io/advisor/npm-package/inquirer
https://snyk.io/vuln/npm:ansi-regex
貢獻指南
研究方向
先檢查 PR #874 以及 inquirer v8.2.0 的相依性參考。確認提議的更新已處理 ansi-regex 的 ReDoS 安全公告,並執行 repository 既有的檢查。易受攻擊的相依性不再被引入且更新已合併,即表示完成。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- javascript, node.js
- 領域
- cli, security
- Issue 類型
- 缺陷
- 難度
- 2/5
- 預估耗時
- 1-3 小時
- 活躍度
- 停滯
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100