Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Has high severity vulnerabilities #4864

Open
NagayamaToshiaki opened this issue Feb 25, 2025 · 0 comments
Open

Has high severity vulnerabilities #4864

NagayamaToshiaki opened this issue Feb 25, 2025 · 0 comments

Comments

@NagayamaToshiaki
Copy link

I installed CodeceptJS at latest, then Node.js showed it has vulnerabirities. I audited and the result is:

# npm audit report

cross-spawn  <6.0.6
Severity: high
Regular Expression Denial of Service (ReDoS) in cross-spawn - https://github.com/advisories/GHSA-3xgq-45jj-v275
fix available via `npm audit fix --force`
Will install codeceptjs@3.5.9, which is a breaking change
node_modules/child-process-promise/node_modules/cross-spawn
  child-process-promise  >=2.2.0
  Depends on vulnerable versions of cross-spawn
  node_modules/child-process-promise
    detox  >=4.1.1
    Depends on vulnerable versions of child-process-promise
    node_modules/detox
      @codeceptjs/detox-helper  *
      Depends on vulnerable versions of detox
      node_modules/@codeceptjs/detox-helper
        codeceptjs  2.2.1 || 3.5.1-2.beta.7 || >=3.5.10
        Depends on vulnerable versions of @codeceptjs/detox-helper
        node_modules/codeceptjs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant