sindresorhus / cpy

Copy files
MIT License
428 stars 63 forks source link

Security issue found in dependency micromatch@4.0.5 #117

Open vergjor opened 3 months ago

vergjor commented 3 months ago

While running a security scan on our application, there was a security issue found for the micromatch@4.0.5 dependency

image

Please update to version micromatch@4.0.6 as soon as possible

vergjor commented 3 months ago

Please also bump the version cpy in the cpy-cli package as well once this is resolved

az-nextsec commented 3 weeks ago

Apparently micromatch 4.0.6 does not resolve that CVE

vergjor commented 3 weeks ago

Apparently micromatch 4.0.6 does not resolve that CVE

which tool are you using for checking for security issues? we are using VeraCode and from what I see from this link it says that 4.0.6 is the version where this issue is resolved

https://sca.analysiscenter.veracode.com/vulnerability-database/security/regular-expression-denial-of-service/javascript/sid-47283

az-nextsec commented 3 weeks ago

@vergjor Github's own advisory that I am getting from npm

https://github.com/advisories/GHSA-952p-6rrq-rcjv