commitizen / commitizen/cz-cli

critical: ReDoS vulnerability from inquirer v8.2.0

未關閉
#883 1 則留言 10 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
JavaScript
星號
17.5k
分支
566
平均合併
8 小時 16 分鐘
30 天內合併 PR
1

描述

Hi Team, there is a high vulnerability found in ansi-regex library for Regular Expression Denial of Service (ReDoS).
This library is used by inquirer v8.2.0.

Please increase the inquirer library to latest version. **Already a PR is open for that, please merge it as soon as possible:**
https://github.com/commitizen/cz-cli/pull/874

Refer the below urls to find more about vulnerability

https://snyk.io/advisor/npm-package/inquirer
https://snyk.io/vuln/npm:ansi-regex

貢獻指南

開啟貢獻指南

研究方向

先檢查 PR #874 以及 inquirer v8.2.0 的相依性參考。確認提議的更新已處理 ansi-regex 的 ReDoS 安全公告,並執行 repository 既有的檢查。易受攻擊的相依性不再被引入且更新已合併,即表示完成。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
javascript, node.js
領域
cli, security
Issue 類型
缺陷
難度
2/5
預估耗時
1-3 小時
活躍度
停滯
描述清晰度
基本清楚
新手友好度
25/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。