Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in dependency trim-newlines #37

Closed
JohnGarnham opened this issue Jun 29, 2021 · 0 comments
Closed

Security vulnerability in dependency trim-newlines #37

JohnGarnham opened this issue Jun 29, 2021 · 0 comments

Comments

@JohnGarnham
Copy link

JohnGarnham commented Jun 29, 2021

Got the following security warning while importing vitejs package

$ npm audit

                       === npm audit security report ===


                                 Manual Review
             Some vulnerabilities require your attention to resolve

          Visit https://go.npm.me/audit-guide for additional guidance


  High            Regular Expression Denial of Service

  Package         trim-newlines

  Patched in      >=3.0.1 <4.0.0 || >=4.0.1

  Dependency of   @vite/vitejs

  Path            @vite/vitejs > conventional-changelog-cli >
                  conventional-changelog > conventional-changelog-core >
                  get-pkg-repo > meow > trim-newlines

  More info       https://npmjs.com/advisories/1753

found 1 high severity vulnerability in 339 scanned packages
  1 vulnerability requires manual review. See the full report for details.
@osdio osdio closed this as completed in 6eaf8dc Jun 30, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant