Upgrade dependency jest-changed-files to fix down-stream security issue with cross-spawn
Open
- Dominant language
- TypeScript
- Stars
- 512
- Forks
- 30
- PR merge metrics
- No merged PRs in 30d
Description
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.