TAMULib / SAGE

Search Aggregation Engine
MIT License
6 stars 1 forks source link

Dependabot: debug Inefficient Regular Expression Complexity vulnerability. #511

Open kaladay opened 1 year ago

kaladay commented 1 year ago

Dependabot detected and attempted to resolve described issue but failed.

see: https://github.com/TAMULib/SAGE/security/dependabot/40

The analysis of the dependency hierarchy looks like this:

npm list --depth=1000 | grep debug
│ │ │ ├── debug@4.3.4 deduped
│ │ │ │ │ ├─┬ debug@2.6.9
│ │ │ ├─┬ debug@2.6.9
│ │ ├─┬ debug@4.3.4
│ │ │ ├─┬ debug@2.6.9
│ │ │ │ ├─┬ debug@2.6.9
│ │ │ ├─┬ debug@2.6.9
│ │ ├─┬ debug@2.6.9
│ │ │ ├─┬ debug@2.6.9
│ │ │ ├─┬ debug@2.6.9
│ │ │ │ │ ├── debug@4.3.4 deduped
│ │ │ │ ├── debug@4.3.4 deduped
│ │ │ ├── debug@4.3.4 deduped
│ │ │ ├─┬ debug@2.6.9
│ │ │ │ ├── debug@2.6.9 deduped
│ │ │ ├── debug@4.3.4 deduped
│ │ │   ├── debug@4.3.4 deduped
│ │ │ ├── debug@4.3.4 deduped
│ │ │ │ ├── debug@4.3.4 deduped
│ │ │   └── debug@4.3.4 deduped
│ │ │ │ │ └── debug@4.3.4 deduped
│ │ │ │ └── debug@4.3.4 deduped
│ │ │ ├─┬ debug@2.6.9
│ │ │ ├── debug@4.3.4 deduped
│ │ │ │ ├── debug@4.3.4 deduped
│ │ │ │ │ ├── debug@4.3.4 deduped
│ │ │ │ │ └── debug@4.3.4 deduped
│ │ │ │ │ ├── debug@4.3.4 deduped
│ │ │   └─┬ debug@3.2.7
│ │ │   └─┬ debug@3.2.7
│ │ ├─┬ debug@3.2.7
│ │   ├─┬ debug@2.6.9
│ │ │ ├─┬ debug@2.6.9
│ │ │ ├── debug@4.3.4 deduped
│ │ │   ├── debug@4.3.4 deduped

We should probably use an override here. Version 4.3.4 is the lates