moul / node-gitlab

DEPRECATED, see https://github.com/node-gitlab/node-gitlab
https://npmjs.org/package/gitlab
Other
470 stars 140 forks source link

Minimatch Regex DoS vulnerability. #152

Closed t-bull closed 5 years ago

t-bull commented 8 years ago

Gitlab dependancy minimatch version 0.2.14 has a regular expression denial of service vulnerability. This seems to be a very early version of the package. The latest version is 3.0.3.

gitlab@1.7.1 > slumber@0.9.0 > yamljs@0.1.6 > glob@3.1.21 > minimatch@0.2.14