arpittyagi102 / Humari-Dukan

Humari Dukan is a E-Commerce website using React with Redux and Bootstrap
https://humaridukan.netlify.app/
MIT License
19 stars 27 forks source link

Help me fix the security issue #34

Open arpittyagi102 opened 1 year ago

arpittyagi102 commented 1 year ago

semver vulnerable to Regular Expression Denial of Service

Upgrade semver to fix 1 Dependabot alert in package-lock.json Upgrade semver to version 7.5.2 or later. For example:

"dependencies": {
  "semver": ">=7.5.2"
}
"devDependencies": {
  "semver": ">=7.5.2"
}

Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.