You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Mar 25, 2021. It is now read-only.
It was found that affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks. This can cause an impact of about 10 seconds matching time for data 48K characters long.
https://bugzilla.redhat.com/show_bug.cgi?id=1552148
Upstream patch is kpdecker/jsdiff@2aec429 which is available in >3.5.0
Is it possible to update the diff package from
^3.2.0
to>= 3.5.0
?Though tslint is used as a tool and we won't have ReDoS it would be good to get this fixed.
The text was updated successfully, but these errors were encountered: