yahoo / yahoo/serialize-javascript
Backport of GHSA-5c6j-r48x-rmvq to version 6
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 2.9k
- Forks
- 215
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 2
Description
Hi, webpack needs a backport of https://github.com/yahoo/serialize-javascript/security/advisories/GHSA-5c6j-r48x-rmvq in order to update and avoid being vulnerable to this issue.
We’re unable to upgrade to version 7 due to our Node.js support (node >=10), which limits us from updating. So would it be possible to please backport this fix?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the GHSA-5c6j-r48x-rmvq advisory and compare its fix with the version 6 code in this repository. Determine the compatible backport for Node.js >=10, then verify that version 6 no longer has the reported vulnerability.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100