serverless / serverless-plugin-log-retention

Control the retention of your serverless function's cloudwatch logs.
MIT License
21 stars 17 forks source link

update semver to address Regular Expression Denial of Service (ReDoS) #14

Open surajsnair92 opened 8 months ago

surajsnair92 commented 8 months ago

semver module for serverless-plugin-log-retention is old. npm audit report shows that it is high on vulnerability.

surajsnair92 commented 8 months ago

Address issue #12 : https://github.com/serverless/serverless-plugin-log-retention/issues/12

gustavosimon commented 2 months ago

Hello @surajsnair92! Thanks for opening this PR, I'm facing the same problem in a repository.

@MichaelRBond Can you approve this PR and release a new version with the fix?

MichaelRBond commented 2 months ago

I can approve the PR, but, i am not a maintainer on this repo so I cannot merge or release a new version.

MichaelRBond commented 2 months ago

cc @ArtificerEntertainment

gustavosimon commented 2 months ago

@MichaelRBond Great, thanks for your quickly response. Let's await to @ArtificerEntertainment to merge and release the fix. We're looking forward to it.

gustavosimon commented 1 month ago

@medikoo Can you merge it?

medikoo commented 1 month ago

@gustavosimon I'm no longer with Serverless Inc. and I don't have rights to manage contributions here. I believe you need to reach out to @austencollins or @mmarzex

gustavosimon commented 1 month ago

@Mmarzex can you merge it?

fedeam commented 1 month ago

@Mmarzex can you merge it?

Jackson3195 commented 3 weeks ago

Any luck with this?

gustavosimon commented 3 weeks ago

I think that as @medikoo saw, @Mmarzex may merge it.