[
https://issues.apache.org/jira/browse/CB-11484?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Shazron Abdullah updated CB-11484:
----------------------------------
Component/s: Coho
> coho test failure (library vulnerability)
> -----------------------------------------
>
> Key: CB-11484
> URL: https://issues.apache.org/jira/browse/CB-11484
> Project: Apache Cordova
> Issue Type: Bug
> Components: Coho
> Reporter: Shazron Abdullah
> Priority: Critical
>
> Our use of [email protected] contains down the tree, a vulnerable library
> [email protected]
> {code}
> (+) 1 vulnerabilities found
> ┌───────────────┬────────────────────────────────────────────────────────────────────────────┐
> │ │ Regular Expression Denial of Service
> │
> ├───────────────┼────────────────────────────────────────────────────────────────────────────┤
> │ Name │ minimatch
> │
> ├───────────────┼────────────────────────────────────────────────────────────────────────────┤
> │ Installed │ 2.0.10
> │
> ├───────────────┼────────────────────────────────────────────────────────────────────────────┤
> │ Vulnerable │ <=3.0.1
> │
> ├───────────────┼────────────────────────────────────────────────────────────────────────────┤
> │ Patched │ >=3.0.2
> │
> ├───────────────┼────────────────────────────────────────────────────────────────────────────┤
> │ Path │ [email protected] > [email protected] > [email protected] >
> [email protected] │
> ├───────────────┼────────────────────────────────────────────────────────────────────────────┤
> │ More Info │ https://nodesecurity.io/advisories/118
> │
> └───────────────┴────────────────────────────────────────────────────────────────────────────┘
> {code}
> Filed for nlf:
> https://github.com/iandotkelly/nlf/issues/40
> Filed for glob-all (which later versions of nlf uses):
> https://github.com/jpillora/node-glob-all/issues/12
> glob-all uses glob, which patched this 4 days ago in 7.0.5:
> https://github.com/isaacs/node-glob/issues/268
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]