Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability reported by snyk #975

Open
juan55860 opened this issue Jan 9, 2018 · 3 comments
Open

Security vulnerability reported by snyk #975

juan55860 opened this issue Jan 9, 2018 · 3 comments

Comments

@juan55860
Copy link

This vulnerability is reported by snyk

Regular Expression Denial of Service (ReDoS)
Vulnerable module: timespan
Introduced through: [email protected]

https://snyk.io/test/npm/forever/0.15.3?severity=high&severity=medium&severity=low

@jamesfiltness
Copy link

jamesfiltness commented Jan 11, 2018

NSP checker also reported this. Looks like it boils down to fsevents needing to update their version of the Tough Cookie package: There's an open issue here: fsevents/fsevents#187

The dependency chain looks like this:
[email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected]

@rahul-desai3
Copy link

I created #960 to handle the vulnerabilities reported by NSP and SNYK.

@kibertoad
Copy link
Contributor

Addressed by #1014

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants