semantic-release / semantic-release/release-notes-generator
CVE-2021-23425
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 368
- Forks
- 55
- Avg merge
- 10m
- Merged PRs (30d)
- 1
Description
Hey,
I want to report that you have a vulnerability in one of your depencencies:
Title: Uncontrolled Resource Consumption in trim-off-newlines
Severity: moderate
Module: trim-off-newlines
Url: https://github.com/advisories/GHSA-38fc-wpqx-33j7
Vulnerable Version: <=1.0.1
Patched Version: <0.0.0
Path: semantic-release>@semantic-release/release-notes-generator>conventional-commits-parser>trim-off-newlines
As far as I can see the issue is already addressed in the conventional-changelog monorepo: https://github.com/conventional-changelog/conventional-changelog/issues/840 so updating the dependency would solve the problem.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by inspecting the dependency path listed in the issue and the repository's package metadata, then review advisory GHSA-38fc-wpqx-33j7. Done means the vulnerable trim-off-newlines version is no longer resolved through semantic-release > @semantic-release/release-notes-generator > conventional-commits-parser; verify the dependency tree afterward.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100