Skip to content

Bump semver to ^7.5.3 to resolve security vulnerability#285

Open
Tyharo1 wants to merge 1 commit into
ember-cli:masterfrom
Tyharo1:semverVersionBump
Open

Bump semver to ^7.5.3 to resolve security vulnerability#285
Tyharo1 wants to merge 1 commit into
ember-cli:masterfrom
Tyharo1:semverVersionBump

Conversation

@Tyharo1

@Tyharo1 Tyharo1 commented Jun 26, 2023

Copy link
Copy Markdown

The current version of semver being used has a ReDos security vulnerability detected by Snyk. A more recent version of semver resolved this issue (v7.5.2 and above). I bumped the semver version to its latest to resolve the vulnerability (v7.5.3).

For further details on this vulnerability you can view Synks details on it here

@Tyharo1

Tyharo1 commented Jun 28, 2023

Copy link
Copy Markdown
Author

@rwjblue You appear to be the most active in this code base, is there a specific contributer I should tag to potentially discuss/review this PR?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant