Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

hosted-git-info moderate vulnerability #1923

Closed
tatemz opened this issue May 7, 2021 · 1 comment
Closed

hosted-git-info moderate vulnerability #1923

tatemz opened this issue May 7, 2021 · 1 comment

Comments

@tatemz
Copy link

tatemz commented May 7, 2021

Current behavior

npm audit shows moderate issue

https://www.npmjs.com/advisories/1677

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Moderate      │ Regular Expression Deinal of Service                         │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ hosted-git-info                                              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=3.0.8                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ semantic-release [dev]                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ semantic-release > @semantic-release/npm > read-pkg >        │
│               │ normalize-package-data > hosted-git-info                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/1677                            │
└───────────────┴──────────────────────────────────────────────────────────────┘

Expected behavior

Likely not a real security issue (see jestjs/jest#11379 (comment)), but can cause ci pipelines to fail.

Environment

  • semantic-release version:
  • CI environment:
  • Plugins used:
  • semantic-release configuration:
  • CI logs:
@gr2m
Copy link
Member

gr2m commented May 7, 2021

Thanks! Automated PRs to fix the affected version are being created right now

@tatemz tatemz closed this as completed Sep 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants