Skip to content

fix: ReDos regex vulnerability, reported by @DayShift - #741

Merged
gr2m merged 5 commits into
8.xfrom
8.x-redos
Feb 15, 2025
Merged

gr2m merged 5 commits into
8.xfrom
8.x-redos

Conversation

@wolfy1339

Copy link
Copy Markdown
Member

@wolfy1339 wolfy1339 added the Type: Bug Something isn't working as documented label Feb 14, 2025
@wolfy1339
wolfy1339 requested review from gr2m and nickfloyd February 14, 2025 22:32
@github-actions

Copy link
Copy Markdown

πŸ‘‹ Hi! Thank you for this contribution! Just to let you know, our GitHub SDK team does a round of issue and PR reviews twice a week, every Monday and Friday! We have a process in place for prioritizing and responding to your input. Because you are a part of this community please feel free to comment, add to, or pick up any issues/PRs that are labled with Status: Up for grabs. You & others like you are the reason all of this works! So thank you & happy coding! πŸš€

@gr2m
gr2m merged commit 356411e into 8.x Feb 15, 2025
@gr2m
gr2m deleted the 8.x-redos branch February 15, 2025 00:08
@github-actions

Copy link
Copy Markdown

πŸŽ‰ This PR is included in version 8.4.1 πŸŽ‰

The release is available on:

Your semantic-release bot πŸ“¦πŸš€

@wolfy1339

Copy link
Copy Markdown
Member Author

@gr2m @nickfloyd Can you update the security advisory with this fixed version

@aashutoshrathi

Copy link
Copy Markdown

@gr2m @nickfloyd can you update the security advisory for this fixed version? Since CJS users still rely on 8.x.
Thanks πŸ™πŸ»
Since, This refer to this

@wolfy1339

Copy link
Copy Markdown
Member Author

The GHSA was already updated

GHSA-rmvr-2pp2-xj38

Whatever software you are using should be pulling from that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

released on @8.x Type: Bug Something isn't working as documented

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants