Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Regular expression denial of service in scss-tokenizer #18055

Closed
1 task
Tracked by #17647
edmund-dunn opened this issue May 7, 2024 · 2 comments
Closed
1 task
Tracked by #17647

Regular expression denial of service in scss-tokenizer #18055

edmund-dunn opened this issue May 7, 2024 · 2 comments
Assignees
Labels
CMS Team CMS Product team that manages both editor exp and devops content-build Defect Something isn't working (issue type)

Comments

@edmund-dunn
Copy link
Contributor

edmund-dunn commented May 7, 2024

Description

This is partly a discovery ticket. If you find this is blocked because of version issues, especially with node please annotate that in the Confluence page and here in the ticket.

One other package sass-graph depends on an early version of this. Worst case is that two packages need to be upgraded, so this shouldn’t be too difficult.

Acceptance Criteria

  • Upgrade scss-tokenizer to >= 0.4.3
@edmund-dunn edmund-dunn added Defect Something isn't working (issue type) CMS Team CMS Product team that manages both editor exp and devops content-build labels May 7, 2024
@JakeBapple JakeBapple self-assigned this Jun 21, 2024
@JakeBapple
Copy link
Contributor

Currently, I believe the node-sass package requires sass-graph, which requires scss-tokenizer. So I believe we need to update the dependency of the tokenizer and graph within node-sass.

@JakeBapple
Copy link
Contributor

this PR was merged and the work here should be good to go @gracekretschmer-metrostar

department-of-veterans-affairs/content-build#2182

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CMS Team CMS Product team that manages both editor exp and devops content-build Defect Something isn't working (issue type)
Projects
None yet
Development

No branches or pull requests

3 participants