conductor-oss / conductor-oss/javascript-sdk
[GHSA-23c5-xmqv-rm74] minimatch@3.1.2: ReDoS via nested extglobs
- Dominant language
- TypeScript
- Stars
- 58
- Forks
- 20
- Avg merge
- 1d 13h
- Merged PRs (30d)
- 7
Description
## Vulnerability Report
| CVE | Library | Installed | Fixed |
|-----|---------|-----------|-------|
| GHSA-23c5-xmqv-rm74 | minimatch | 3.1.2 | 3.1.4 |
| GHSA-3ppc-4f35-3m26 | minimatch | 3.1.2 | 3.1.3 |
| GHSA-7r86-cg39-jmmj | minimatch | 3.1.2 | 3.1.3 |
### Summary
Three ReDoS vulnerabilities in minimatch (transitive dependency).
### References
- [GHSA-23c5-xmqv-rm74](https://osv.dev/vulnerability/GHSA-23c5-xmqv-rm74)
- [GHSA-3ppc-4f35-3m26](https://osv.dev/vulnerability/GHSA-3ppc-4f35-3m26)
- [GHSA-7r86-cg39-jmmj](https://osv.dev/vulnerability/GHSA-7r86-cg39-jmmj)
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.