Skip to content

ReDOS on micromatch/braces (reported on Feb 15th 2019) #7917

Closed
@ranand

Description

@ranand

🐛 Bug Report

I have been noticing https://nodesecurity.io/advisories/786 warnings since yesterday. It looks like braces project had an update (micromatch/braces@abdafb0) to fix the ReDOS issue as well. Is there any chance Jest will update micromatch/braces to fix these warnings?

To Reproduce

135 vulnerabilities found - Packages audited: 52247
Severity: 135 Low
✨  Done in 1.58s.

Screenshot from terminal:
screen shot 2019-02-16 at 2 52 06 pm

Expected behavior

Link to repl or repo (highly encouraged)

See above.
braces fix link: micromatch/braces@abdafb0

Run npx envinfo --preset jest

  System:
    OS: macOS 10.14.2
    CPU: (8) x64 Intel(R) Core(TM) i7-8559U CPU @ 2.70GHz
  Binaries:
    Node: 11.6.0 - ~/.nvm/versions/node/v11.6.0/bin/node
    Yarn: 1.13.0 - /usr/local/bin/yarn
    npm: 6.8.0 - ~/.nvm/versions/node/v11.6.0/bin/npm
  npmPackages:
    jest: ^23.6.0 => 23.6.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions