kevva / kevva/bin-wrapper

Outdated `bin-version-check` dependency - needs version bumping

Open
#82 2 comments 10 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
152
Forks
65
PR merge metrics
No merged PRs in 30d

Description

I believe the `bin-version-check` package should be updated to the latest version of 5.0.0 which would remove the high CVE found [here](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3795) caused by a downstream dependency `semver-regex`
Screen Shot 2022-06-07 at 12 39 00 AM

Contributor guide

No contributing guide indexed for this repository

Research direction

Locate the dependency manifest for bin-wrapper and inspect how bin-version-check is declared and resolved. Update it to 5.0.0, then verify that the downstream semver-regex vulnerability identified by CVE-2021-3795 is no longer present in the dependency tree.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security, tooling
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.