Skip to content
This repository was archived by the owner on Aug 4, 2021. It is now read-only.
This repository was archived by the owner on Aug 4, 2021. It is now read-only.

Vulnerability coming from micromatch > braces #51

Description

@XhmikosR
 Low             Regular Expression Denial of Service

 Package         braces

 Patched in      >=2.3.1

 Dependency of   rollup-plugin-babel [dev]

 Path            rollup-plugin-babel > rollup-pluginutils > micromatch >
                 braces

 More info       https://nodesecurity.io/advisories/786

...which is weird since I see you already target micromatch ^2.3.1. I've tried cleaning up local node_modules and package-lock.json and doing npm i, same thing.

Maybe the advisory has the wrong info?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions