Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

semver security warning #351

Open
hildjj opened this issue Jun 24, 2023 · 3 comments
Open

semver security warning #351

hildjj opened this issue Jun 24, 2023 · 3 comments

Comments

@hildjj
Copy link

hildjj commented Jun 24, 2023

semver < 7.5.2 has vulnerability due to a ReDoS. You're currently on 6.1.0.

Please take a look at #345 at the same time.

@SilPho
Copy link

SilPho commented Jul 5, 2023

If upgrading to Semver 7 isn't possible, there is a V6 backfix available under a different package name:
https://www.npmjs.com/package/@nicolo-ribaudo/semver-v6

Further discussion on backports can be found here:
npm/node-semver#564

@hildjj
Copy link
Author

hildjj commented Jul 5, 2023

For others following this, I'm switching to https://github.com/eslint-community/eslint-plugin-n#readme wherever I can.

@voxpelli
Copy link

voxpelli commented Aug 13, 2023

Yeah eslint-plugin-n is the maintained version of this module. We switched to it in eg. eslint-config-standard / standard and it is maintained by the official ESLint community organization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants