-
Notifications
You must be signed in to change notification settings - Fork 18
update semver to address Regular Expression Denial of Service (ReDoS) #14
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Hello @surajsnair92! Thanks for opening this PR, I'm facing the same problem in a repository. @MichaelRBond Can you approve this PR and release a new version with the fix? |
I can approve the PR, but, i am not a maintainer on this repo so I cannot merge or release a new version. |
@MichaelRBond Great, thanks for your quickly response. Let's await to @ArtificerEntertainment to merge and release the fix. We're looking forward to it. |
@medikoo Can you merge it? |
@gustavosimon I'm no longer with Serverless Inc. and I don't have rights to manage contributions here. I believe you need to reach out to @austencollins or @Mmarzex |
@Mmarzex can you merge it? |
1 similar comment
@Mmarzex can you merge it? |
Any luck with this? |
Will this fix be merged any time soon ? @austencollins @Mmarzex |
Waiting for the merge here too |
We've scheduled this to be reviewed an merged over the next few days. thanks for the notifications. |
Published to npm. |
semver module for serverless-plugin-log-retention is old. npm audit report shows that it is high on vulnerability.