Outdated `bin-version-check` dependency - needs version bumping
Open
- Dominant language
- JavaScript
- Stars
- 152
- Forks
- 65
- PR merge metrics
- No merged PRs in 30d
Description
I believe the `bin-version-check` package should be updated to the latest version of 5.0.0 which would remove the high CVE found [here](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3795) caused by a downstream dependency `semver-regex`
Contributor guide
No contributing guide indexed for this repository
Research direction
Locate the dependency manifest for bin-wrapper and inspect how bin-version-check is declared and resolved. Update it to 5.0.0, then verify that the downstream semver-regex vulnerability identified by CVE-2021-3795 is no longer present in the dependency tree.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100