marcoandre1 / react-snap

👻 Zero-configuration framework-agnostic static prerendering for SPAs
MIT License
1 stars 0 forks source link

Update html-minifier #22

Closed marcoandre1 closed 2 weeks ago

marcoandre1 commented 2 weeks ago

For security reasons, we need to update this dependency.

marcoandre1 commented 2 weeks ago

GitHub Advisory Database / GitHub Reviewed / CVE-2022-37620

kangax html-minifier REDoS vulnerability

High severity GitHub Reviewed

Published Oct 31, 2022 to the GitHub Advisory Database • Updated Apr 22, 2024

Package : html-minifier (npm) Affected versions : <= 4.0.0 Patched versions : None

Description

A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 via the candidate variable in htmlminifier.js.

References

DanielRuf commented 4 days ago

I suggest reading my comments and especially https://github.com/kangax/html-minifier/issues/1135#issuecomment-2453437884 - because switching to html-minifier-terser will not fix this.