Closed vycos-zen closed 2 years ago
Yeah, this vulnerability has been promoted from moderate
to high
, so looks like it should be addressed.
This scss-tokenizer fork claims to have a fix. 🤞 it will be accepted upstream.
It was merged, now we just need update the dependency version in sass-graph. @xzyfer would you be able to do it, pretty please? 🙏
Can somebody please provide an ETA on when this can be done?
Fixed in v4.0.1
Fixed in v4.0.1
Thank you very much.
sweet! thank you.
reference: CVE-2022-25758
Regular expression denial of service in scss-tokenizer
symptom: yarn.lock indicates a dependency to scss-tokenizer: ^0.3.0, trigering a dependabot warning
Severity High 7.5/ 10
scss-tokenizer current version is 0.4.2
impacted packages
expected outcome: no safety warning to the package.
is it possible to update this package?