Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Contribution to "Uncontrolled Resource Consumption in ansi-html" #57

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

Diddern
Copy link

@Diddern Diddern commented Mar 2, 2022

Updates

  • Add patched version

@github-actions github-actions bot changed the base branch from main to Diddern/advisory-improvement-57 March 2, 2022 12:24
@darakian
Copy link
Contributor

darakian commented Mar 2, 2022

Hey there. Do you have a reference supporting this change?

@Diddern
Copy link
Author

Diddern commented Mar 3, 2022

@darakian Tjatse/ansi-html@8142b25 merges a patch for CVE-2021-23424, and bumps to v0.0.8.
0.0.9 is newest non-breaking change.

@darakian
Copy link
Contributor

darakian commented Mar 3, 2022

@Diddern that would make 0.0.8 the first patched version then right?

@Diddern
Copy link
Author

Diddern commented Mar 7, 2022

@darakian yes that is correct.
However 0.0.9 removes lodash as devDependency and refactors a test, so I see no problem with using 0.0.9 as prefered version. This effectivly removes GHSA-29mw-wpgm-hmr9
Tjatse/ansi-html@25ffe44

@darakian
Copy link
Contributor

darakian commented Mar 8, 2022

I see no problem with using 0.0.9 as prefered version.

Sure, but as far as the accuracy of this vulnerability is concerned 0.0.8 is the correct patch version. I'll update the advisory to reflect.

@advisory-database advisory-database bot merged commit ebd056c into Diddern/advisory-improvement-57 Mar 8, 2022
@advisory-database advisory-database bot deleted the Diddern-GHSA-whgm-jr23-g3j9 branch March 8, 2022 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants