commitizen / commitizen/cz-conventional-changelog

word-wrap version change not available in NPM but available in Github | word-wrap vulnerable to Regular Expression Denial of Service

Open
#242 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
793
Forks
444
PR merge metrics
No merged PRs in 30d

Description

The following link shows older version for word-wrap i.e version "word-wrap": "^1.0.3"

![Image](https://github.com/user-attachments/assets/762a70b8-2c1e-41bf-a0b0-8c4750fcbe14)

The same package has been bumped in the latest master branch of the
[cz-conventional-changelog](https://github.com/commitizen/cz-conventional-changelog)

The older version has been flagged to have the following issue:

word-wrap vulnerable to Regular Expression Denial of Service

Reference:

https://github.com/advisories/GHSA-j8xg-fqg3-53r7

Contributor guide

No contributing guide indexed for this repository

Research direction

Compare the published npm package with the latest master branch of cz-conventional-changelog and inspect where the word-wrap dependency is declared. Confirm whether the vulnerable ^1.0.3 version is still published or used, then verify that the available update removes the referenced Regular Expression Denial of Service advisory.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
cli
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.