minio / minio-js

MinIO Client SDK for Javascript
https://docs.min.io/docs/javascript-client-quickstart-guide.html
Apache License 2.0
963 stars 282 forks source link

fix: fast-xml-parser version #1335

Closed mirpo closed 3 months ago

mirpo commented 3 months ago

Even though this PR was merged https://github.com/minio/minio-js/pull/1328 npm pulls "fast-xml-parser": "^4.2.2" from package.json Which has Regular Expression Denial of Service (ReDoS) https://security.snyk.io/package/npm/fast-xml-parser

Screenshot 2024-08-14 at 15 17 19