Skip to content

[Bug]: semver dep security vulnerability #3589

Closed as not planned
Closed as not planned
@AviVahl

Description

@AviVahl

Is there an existing issue for this?

  • I have searched the existing issues and my issue is unique
  • My issue appears in the command-line and not only in the text editor

Description Overview

When installing package using npm, audit fails with:

$ npm audit
# npm audit report

semver  <7.5.2
Severity: moderate
semver vulnerable to Regular Expression Denial of Service - https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
fix available via `npm audit fix --force`
Will install eslint-plugin-react@7.25.3, which is a breaking change
node_modules/semver
  eslint-plugin-react  7.19.0 || >=7.26.0
  Depends on vulnerable versions of semver
  node_modules/eslint-plugin-react

2 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force

Running npm audit fix --force downgrades to eslint-plugin-react@7.25.3 👀

Expected Behavior

No security vulnerabilities.

eslint-plugin-react version

7.32.2

eslint version

8.43.0

node version

18.16.1

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions