ncs-northware / northware

Manage the NCS Bussiness
https://ncs-northware.github.io/northware/
0 stars 0 forks source link

[Security]: Denial of service in http-proxy-middleware #153

Open onissen opened 1 week ago

onissen commented 1 week ago

Link zum Dependbot Alert

https://github.com/ncs-northware/northware/security/dependabot/5

Schweregrad

High

Betroffenes Package

@eslint-community/eslint-utils@4.4.0

northware@ 
└─┬ @eslint-community/eslint-utils@4.4.0 extraneous -> .\node_modules\.pnpm\@eslint-community+eslint-utils@4.4.0_eslint@9.14.0_jiti@1.21.6_\node_modules\@eslint-community\eslint-utils
  └─┬ eslint@9.14.0 invalid: "^8.28.0" from node_modules/.pnpm/@eslint-community+eslint-utils@4.4.0_eslint@9.14.0_jiti@1.21.6_/node_modules/@eslint-community/eslint-utils -> .\node_modules\.pnpm\eslint@9.14.0_jiti@1.21.6\node_modules\eslint
    └─┬ webpack@5.95.0 invalid: "^1.15.0" from node_modules/.pnpm/source-map-support@0.5.21/node_modules/source-map-support, "^4.31.0" from node_modules/.pnpm/rxjs@7.8.1/node_modules/rxjs, "~1.14.0" from node_modules/.pnpm/esprima@4.0.1/node_modules/esprima -> .\node_modules\.pnpm\webpack@5.95.0\node_modules\webpack
      └─┬ mini-css-extract-plugin@2.9.1 -> .\node_modules\.pnpm\mini-css-extract-plugin@2.9.1_webpack@5.95.0\node_modules\mini-css-extract-plugin
        └─┬ webpack-dev-server@4.15.2 -> .\node_modules\.pnpm\webpack-dev-server@4.15.2_webpack@5.95.0\node_modules\webpack-dev-server
          └── http-proxy-middleware@2.0.6 -> .\node_modules\.pnpm\http-proxy-middleware@2.0.6_@types+express@4.17.21\node_modules\http-proxy-middleware

Beschreibung

Das Package wird von einer ESLint dependency verwendet. Vielleicht erledigt sich das Problem von selbst, wenn klar ist, was mit @northware/eslint-config passieren soll (#144)