Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Regular Expression Denial of Service Vulnerability in Dependency #48

Closed
randompixel opened this issue Jul 4, 2023 · 2 comments
Closed

Comments

@randompixel
Copy link

Synk is reporting a vulnerability from this package as it depends on Word Wrap 1.2.3

eslint@8.33.0 › optionator@0.9.1 › word-wrap@1.2.3

The advisory for this issue is here GHSA-j8xg-fqg3-53r7 and it appears it was fixed in Word Wrap 1.2.4

Any chance you could update the dependencies and release a new version?

Thanks,

@12beesinatrenchcoat
Copy link

12beesinatrenchcoat commented Jul 4, 2023

Should have been fixed with #46 (switching to temporary fork with fix, see also jonschlinkert/word-wrap#33).
word-wrap 1.2.4 does not (yet) exist. Fork is on version 1.2.6, which should be installed when you install/update dependencies.

@randompixel
Copy link
Author

Great, thanks :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants