Closed gemaxim closed 4 months ago
Instead of matching (..) groups, which has a redos vulnerability, split string by "(". This gets the string till the first occurence of "(". This works just fine because a package name cannot have "(" in its name (it shows up just as a separator).
:tada: This PR is included in version 1.53.3 :tada:
The release is available on:
Your semantic-release bot :package::rocket:
What this does
Instead of matching (..) groups, which has a redos vulnerability, split string by "(". This gets the string till the first occurence of "(". This works just fine because a package name cannot have "(" in its name (it shows up just as a separator).