Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

postcss Denial of Service #203

Closed
TerrenceBerg opened this issue May 20, 2021 · 2 comments
Closed

postcss Denial of Service #203

TerrenceBerg opened this issue May 20, 2021 · 2 comments

Comments

@TerrenceBerg
Copy link

I have a problem with "postcss": "^7.0.35",
When I run npm audit this is what I get.
postcss 7.0.0 - 8.2.9
Severity: moderate
Regular Expression Denial of Service - https://npmjs.com/advisories/1693
fix available via npm audit fix --force
Will install resolve-url-loader@2.3.2, which is a breaking change
node_modules/resolve-url-loader/node_modules/postcss
resolve-url-loader 3.0.0-alpha.1 - 4.0.0
Depends on vulnerable versions of postcss
node_modules/resolve-url-loader

@bholloway
Copy link
Owner

Please refer to #198 for solutions

@TerrenceBerg
Copy link
Author

TerrenceBerg commented May 20, 2021 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants