minio / minio-js

MinIO Client SDK for Javascript
https://docs.min.io/docs/javascript-client-quickstart-guide.html
Apache License 2.0
932 stars 274 forks source link

fix: fast-xml-parser version #1335

Closed mirpo closed 1 month ago

mirpo commented 1 month ago

Even though this PR was merged https://github.com/minio/minio-js/pull/1328 npm pulls "fast-xml-parser": "^4.2.2" from package.json Which has Regular Expression Denial of Service (ReDoS) https://security.snyk.io/package/npm/fast-xml-parser

Screenshot 2024-08-14 at 15 17 19