d-rec / drec-origin

D-REC Origin
https://d-rec.github.io/drec-origin/
GNU General Public License v3.0
8 stars 1 forks source link

Fix Required: axios Inefficient Regular Expression Complexity vulnerability #108 #329

Open Aish1990 opened 5 months ago

Aish1990 commented 5 months ago

There are some libraries which has axios as it's peer dependency.

@nestjs/axios/0.0.8_v3qn2ycuolalzlasoowzcfuity => axios: 0.27.2
@energyweb/origin-backend/11.0.2-alpha.1634225870.0_swagger-ui-express@4.1.6 => @nestjs/common/7.6.18_7pezqkmxxiste2pslpodjdfzhq => axios: 0.21.1
@energyweb/origin-backend-utils/1.6.2-alpha.1634225870.0_ebqzonq2psrptj7354jhe34g5u => @nestjs/common/7.6.18_ffvobmkjg3th6prrgx4ip7zviy => axios: 0.21.1
@energyweb/origin-backend-utils/1.6.2-alpha.1634225870.0_ebqzonq2psrptj7354jhe34g5u => @nestjs/config/1.0.2_4sr75ff4axfz5ra5nhvczaxalu => @nestjs/common/7.6.18_ffvobmkjg3th6prrgx4ip7zviy => axios: 0.21.1
@energyweb/origin-backend-utils/1.6.2-alpha.1634225870.0_ebqzonq2psrptj7354jhe34g5u => @nestjs/core/7.6.18_gwggahupp437j5mwmtjcwxy6w4 => @nestjs/common/7.6.18_ffvobmkjg3th6prrgx4ip7zviy => axios: 0.21.1
@energyweb/issuer-api/0.6.2-alpha.1646058469.0_xopg3sgvptdwdhuxuxidphnbby => @nestjs/common/8.1.1_q6s47l4nyhjovs6nshw3c2acbu: => axios: 0.23.0
@energyweb/energy-api-influxdb/0.8.3_5s24yubn6oroycelimerxxvadu => @nestjs/common/8.2.4_4qssliailtvlb2yasub5vaxiha =>       axios: 0.24.0
wait-on/5.2.1 => axios: 0.21.4

[!NOTE] We have already upgraded the axios greater than the patched version >0.21.2. But @energyweb/origin-backend-utils is incompatible with the patched version.

So We need to resolve it only when the@energyweb/origin-backend-utils releases which is compatible with axios>0.21.2.