paulmillr / chokidar

Minimal and efficient cross-platform file watching library
https://paulmillr.com
MIT License
11.04k stars 586 forks source link

[CVE-2024-4068] Lib braces with problem #1344

Closed BrunoHenriqueSouza closed 3 months ago

BrunoHenriqueSouza commented 3 months ago

Problem:

In the last version, chokidar import 3.0.2 of braces library . This library have an issue described in CVE-2024-4068.

Versions (please complete the following information):

To Reproduce:

Run npm install in project that use chokidar library. After, run npm audit and the result will be:

braces <3.0.3 Severity: high Uncontrolled resource consumption in braces - https://github.com/advisories/GHSA-grv7-fg5c-xmjg