jonkemp / jonkemp/inline-css

DoS vulnerability via obsolete "css-what" version

Open
#104 2 comments 2 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
438
Forks
77
PR merge metrics
No merged PRs in 30d

Description

Hello Maintainers,

I want to get this on your radar: `npm audit` is failing for vulnerability in `css-what` package

I saw cheerio is working on fixing it [here](https://github.com/cheeriojs/cheerio/issues/1924) and looking forward for` inline-css ` to incorporate this update and resolve vulnerability

| High | Denial of Service |
| ----- | --------------------- |
| Package | css-what |
| Patched in | >=5.0.1 |
| Dependency of | inline-css |
| Path | inline-css > cheerio > css-select > css-what |
| More Info | https://npmjs.com/advisories/1754 |

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.