Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

hosted-git-info moderate vulnerability #11383

Closed
ammal617 opened this issue May 7, 2021 · 3 comments
Closed

hosted-git-info moderate vulnerability #11383

ammal617 opened this issue May 7, 2021 · 3 comments

Comments

@ammal617
Copy link

ammal617 commented May 7, 2021

Hello,

We have noticed a moderate vulnerability regarding a sub-dependancy to jest (hosted-git-info). https://npmjs.com/advisories/1677
Is there a plan to upgrade hosted-git-info to a version that do not have this vulnerability ?

Kind regards

@MrCheater
Copy link

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ moderate │ Regular Expression Deinal of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ hosted-git-info │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=3.0.8 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ jest │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ jest > jest-cli > @jest/core > jest-resolve > read-pkg-up > │
│ │ read-pkg > normalize-package-data > hosted-git-info │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1677
└───────────────┴──────────────────────────────────────────────────────────────┘

@SimenB
Copy link
Member

SimenB commented May 7, 2021

#11379 (comment)

@SimenB SimenB closed this as completed May 7, 2021
@github-actions
Copy link

github-actions bot commented Jun 7, 2021

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.
Please note this issue tracker is not a help forum. We recommend using StackOverflow or our discord channel for questions.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jun 7, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants