Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update to at least version 1.1.0 of tiny-lr to avoid Regular Expression Denial of Service #135

Open
shawn-peery opened this issue Jun 10, 2019 · 0 comments

Comments

@shawn-peery
Copy link

shawn-peery commented Jun 10, 2019

https://www.npmjs.com/advisories/534

When using gulp-server 0.9.1, there is a vulnerability for the version of tiny-lr being used.

Low | Regular Expression Denial of Service
Package | debug
Patched in │ >= 2.6.9 < 3.0.0 || >= 3.1.0
Dependency of │ gulp-webserver [dev]
Path │ gulp-webserver > tiny-lr > debug
More info │ https://nodesecurity.io/advisories/534

I didn't see a previous issue for this on the tracker. If I'm mistaken, please let me know.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant