Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Patch -> CVE-2023-43646 #4302

Closed
6 tasks done
lernerb opened this issue Oct 13, 2023 · 2 comments · Fixed by #4358
Closed
6 tasks done

Security Patch -> CVE-2023-43646 #4302

lernerb opened this issue Oct 13, 2023 · 2 comments · Fixed by #4358

Comments

@lernerb
Copy link

lernerb commented Oct 13, 2023

Describe the bug

Dependabot is sending out notifications to all users of vitest on the latest version:

Chaijs/get-func-name vulnerable to ReDoS #553
Open Opened 2 weeks ago on get-func-name (npm)
Dependabot cannot update get-func-name to a non-vulnerable version
The latest possible version of get-func-name that can be installed is 2.0.0.
The earliest fixed version is 2.0.1.

Loupe just published the latest version today: https://github.com/chaijs/loupe/releases/tag/v2.3.7

Need to update utils & locks to match that fix so folks can upgrade without patching/overriding.

https://github.com/vitest-dev/vitest/blob/main/packages/utils/package.json#L55

Reproduction

Turn on Dependabot.

System Info

N/A

Used Package Manager

npm

Validations

@AriPerkkio
Copy link
Member

Need to update utils & locks to match that fix so folks can upgrade without patching/overriding.

Loupe's fix is a patch release. Can't you just update your lockfile and use latest version of Loupe?

@lernerb
Copy link
Author

lernerb commented Oct 16, 2023

@AriPerkkio That's definitely a solution - we don't depend on it directly, so figured it may be simpler and better for the rest of the community if we can also bump the minimum patch version directly here as well so folks automatically get the update!

@sheremet-va sheremet-va mentioned this issue Oct 24, 2023
6 tasks
@github-actions github-actions bot locked and limited conversation to collaborators Nov 8, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants