hfour / hfour/wsrun

Upgrade dependency jest-changed-files to fix down-stream security issue with cross-spawn

Open
#118 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
512
Forks
30
PR merge metrics
No merged PRs in 30d

Description

Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.