registreerocks / registree-core

0 stars 0 forks source link

chore(deps): update ssri 8.0.0 → 8.0.1 #382

Closed PiDelport closed 3 years ago

PiDelport commented 3 years ago

This is a security update for CVE-2021-27290, Regular Expression Denial of Service (ReDoS):

ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, leading to denial of service. This issue only affects consumers using the strict option.

codecov[bot] commented 3 years ago

Codecov Report

Merging #382 (29bef41) into staging (aafe6c5) will not change coverage. The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff            @@
##           staging     #382   +/-   ##
========================================
  Coverage    75.88%   75.88%           
========================================
  Files          144      144           
  Lines         2335     2335           
  Branches       181      181           
========================================
  Hits          1772     1772           
  Misses         562      562           
  Partials         1        1           

Continue to review full report at Codecov.

Legend - Click here to learn more Δ = absolute <relative> (impact), ø = not affected, ? = missing data Powered by Codecov. Last update aafe6c5...29bef41. Read the comment docs.