Skip to content
This repository has been archived by the owner on Jul 9, 2022. It is now read-only.

CVE on jison #7

Open
IanMeyers opened this issue Oct 19, 2020 · 0 comments
Open

CVE on jison #7

IanMeyers opened this issue Oct 19, 2020 · 0 comments

Comments

@IanMeyers
Copy link

The regex package has a transitive or direct dependency on jison, which is subject to a CVE that is causing Github Dependabot alerts: GHSA-vr9x-mm65-2438. I don't see that there is an update to jison for you to take advantage of, but is this something that you can look to mitigate?

Thx!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant