Skip to content

fix: eliminate ReDoS - #36

Merged
phated merged 1 commit into
gulpjs:mainfrom
Trott:snyk-fix-patch
Mar 6, 2021
Merged

fix: eliminate ReDoS#36
phated merged 1 commit into
gulpjs:mainfrom
Trott:snyk-fix-patch

Conversation

@Trott

@Trott Trott commented Feb 10, 2021

Copy link
Copy Markdown
Contributor

This change fixes a regular expression denial of service
vulnerability.

Refs: #32
Refs: https://app.snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905

This change fixes a regular expression denial of service
vulnerability.

Refs: gulpjs#32
Refs: https://app.snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905
@j-sp4

This comment has been minimized.

@phated

phated commented Feb 18, 2021

Copy link
Copy Markdown
Member

Hey @Spoor2709, there is none.

@j-sp4

j-sp4 commented Feb 18, 2021

Copy link
Copy Markdown

Hey @Spoor2709, there is none.

@phated thanks for the reply! Waiting on this to be merged to introduce a big feature in the snyk CLI. Let is there anything I or my team can do to help get this in?

@Trott

Trott commented Feb 19, 2021

Copy link
Copy Markdown
Contributor Author

@phated Based on #34 (comment), I've been hoping the plan is to land this as a patch fix, and then include #34 (which I'll rebase after this lands) as part of a major version bump. Is that at least still under consideration, even if there's no eta?

@phated

phated commented Feb 19, 2021

Copy link
Copy Markdown
Member

@Trott It's still on the plate and I appreciate your work. I'm just swamped right now and don't appreciate people that didn't write the PRs hounding me about doing work for free. Again, thanks for this and I'll try to get to is ASAP.

@Trott

Trott commented Mar 3, 2021

Copy link
Copy Markdown
Contributor Author

Ping to see if there's a chance of moving this forward at this time. No particular urgency on my end. Just checking in. @phated

@phated

phated commented Mar 6, 2021

Copy link
Copy Markdown
Member

Thanks @Trott - sorry for the delay! I'm finally getting caught up on things. Let me know once #34 is rebased and I'll get that in a major.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants