Skip to content

High Vulnerability - nth-check Regular Expression Denial of Service (ReDoS) #12948

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
GowthamiAmp opened this issue Jan 5, 2023 · 3 comments · May be fixed by #13778
Open

High Vulnerability - nth-check Regular Expression Denial of Service (ReDoS) #12948

GowthamiAmp opened this issue Jan 5, 2023 · 3 comments · May be fixed by #13778

Comments

@GowthamiAmp
Copy link

react-scripts dependency package used [email protected] which is having high Vulnerability. But nth-check upgraded version has no vulnerability.
So please check the possibility to fix this vulnerability.

Path:
[email protected] › @svgr/[email protected] › @svgr/[email protected][email protected][email protected][email protected]

image

@tomdelahaba
Copy link

tomdelahaba commented Jan 12, 2023

Seems the react-scripts team does not care about vulnerabilities there are more of them which are vulnerable, for example loader-utils as well which should be already updated to 3.x... it is (just today) 9 months since the last version release! No single minor version released, no info, nothing...

@jzombie
Copy link

jzombie commented Jan 18, 2023

I have a suspicion the project is no longer being maintained: https://news.ycombinator.com/item?id=34421816

@WilliamPriorielloGarda
Copy link

See #11174

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
4 participants