Skip to content

Regular Expression Denial of Service (ReDoS) in cross-spawn #65

@pandektes-braedon

Description

@pandektes-braedon

Description

I'm seeing the above vulnerability in my repo after I've started using your file picker component which depends on this repo.
The full warning from dependabot is:

@apideck/file-picker@1.0.3 requires cross-spawn@^6.0.5 via a transitive dependency on patch-package@6.5.1

Do you have plans to look at updating your usage of patch-package to a patched version? Would greatly appreciate the fix here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions