jleeson / rollup-plugin-html-literals

A Rollup plugin to minify html template literals
MIT License
9 stars 0 forks source link

Html-minifier high severity vulnerability #5

Open gabrieladeegloo opened 2 months ago

gabrieladeegloo commented 2 months ago

html-minifier *

Severity: high

kangax html-minifier REDoS vulnerability - https://github.com/advisories/GHSA-pfq8-rq6v-vf5m

No fix available

node_modules/html-minifier

minify-html-literals *

Depends on vulnerable versions of html-minifier

node_modules/minify-html-literals

rollup-plugin-html-literals *

Depends on vulnerable versions of minify-html-literals

node_modules/rollup-plugin-html-literals

jleeson commented 2 months ago

This is a dependency of minify-html-literals, I will keep this issue open until a fix is available.