Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does it possible to update semver depcy from anything to 7.5.2? #78

Open
dc185334 opened this issue Jun 22, 2023 · 6 comments · May be fixed by #81
Open

Does it possible to update semver depcy from anything to 7.5.2? #78

dc185334 opened this issue Jun 22, 2023 · 6 comments · May be fixed by #81

Comments

@dc185334
Copy link

I have no issues with such npm overrides in my package.json, but it is still my case:

    "semver@7.5.1": "7.5.2",
    "cls-hooked@4.2.2": {
      "semver@5.4.1": "7.5.2"
    },
    "async-listener@0.6.10": {
      "semver@5.7.1": "7.5.2"
    }
@rpodwika
Copy link

semver 5.4.1 seem to have CVE https://www.mend.io/vulnerability-database/CVE-2022-25883 any chane to update that dependency?

@gutierrezj2
Copy link

having same issue +1

@Regnised
Copy link

Regnised commented Jul 7, 2023

Having the snyk issue
Regular Expression Denial of Service (ReDoS) [High Severity][https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795] in semver@7.5.1
introduced by aws-xray-sdk@3.5.0 > aws-xray-sdk-core@3.5.0 > cls-hooked@4.2.2 > semver@5.7.1 and 1 other path(s)
This issue was fixed in versions: 7.5.2

@dc185334
Copy link
Author

dc185334 commented Jul 7, 2023

7.5.2 force resolution works like a charm for the last two weeks. Just letting you to know.

@rohitkumarcs
Copy link

What is the plan to release the fix of this issue anytime soon?

@rsshilli
Copy link

There's a pull request (#81) that's been sitting there for a month. I'm guessing the author has abandoned this project :-(.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

6 participants