-
Notifications
You must be signed in to change notification settings - Fork 5
Open
Description
minimatch <10.2.1
Severity: high
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - https://github.com/advisories/GHSA-3ppc-4f35-3m26
fix available via `npm audit fix --force`
Will install eslint@4.1.1, which is a breaking change
node_modules/minimatch
node_modules/sucrase/node_modules/minimatch
@humanwhocodes/config-array *
Depends on vulnerable versions of minimatch
node_modules/@humanwhocodes/config-array
glob 3.0.0 - 10.5.0
Depends on vulnerable versions of minimatch
node_modules/glob
node_modules/sucrase/node_modules/glob
rimraf 2.3.0 - 3.0.2 || 4.2.0 - 5.0.10
Depends on vulnerable versions of glob
node_modules/rimraf
flat-cache 1.3.4 - 4.0.0
Depends on vulnerable versions of rimraf
node_modules/flat-cache
file-entry-cache 4.0.0 - 7.0.2
Depends on vulnerable versions of flat-cache
node_modules/file-entry-cache
sucrase 3.13.0 - 3.35.0
Depends on vulnerable versions of glob
node_modules/sucrase
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels