Semantic-Org / Semantic-UI

Semantic is a UI component framework based around useful principles from natural language.
http://www.semantic-ui.com
MIT License
51.12k stars 4.94k forks source link

gulp-watch has vulnerabilities and last commit 1 jan 2019 #6844

Open ComLock opened 5 years ago

ComLock commented 5 years ago
│ Low           │ Regular Expression Denial of Service                         │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ braces                                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=2.3.1                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ semantic-ui [dev]                                            │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ semantic-ui > gulp-watch > anymatch > micromatch > braces    │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/786                             │
└───────────────┴──────────────────────────────────────────────────────────────┘

The below issue is not beeing solved by the package maintainer: https://github.com/floatdrop/gulp-watch/issues/321

I don't know the proper solution, but here are some ideas:

lubber-de commented 5 years ago

FYI, https://fomantic-ui.com has been upgraded to gulp 4 already which depends on braces 2.3.2