Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability: Update dependencies on @commitlint/core, @commitlint/cli and semantic-release #27

Open
dbartholomae opened this issue Sep 7, 2019 · 0 comments

Comments

@dbartholomae
Copy link

Currently the package relies on version 6.x of semantic-release, @commitlint/core and @commitlint/cli. These contain the below vulnerabilities. Please update these dependencies to newer versions.
You can also use audit-ci in your CircleCI config to be automatically warned on builds.

moderate Regular Expression Denial of Service
Package marked
Patched in >=0.6.2
Dependency of semantic-commitlint
Path semantic-commitlint > semantic-release > marked
More info https://www.npmjs.com/advisories/812
high Prototype Pollution
Package lodash.merge
Patched in >=4.6.2
Dependency of semantic-commitlint
Path semantic-commitlint > @commitlint/cli > @commitlint/load > @commitlint/resolve-extends > lodash.merge
More info https://www.npmjs.com/advisories/1066
high Prototype Pollution
Package lodash.merge
Patched in >=4.6.2
Dependency of semantic-commitlint
Path semantic-commitlint > @commitlint/core > @commitlint/load > @commitlint/resolve-extends > lodash.merge
More info https://www.npmjs.com/advisories/1066
high Prototype Pollution
Package lodash.merge
Patched in >=4.6.2
Dependency of semantic-commitlint
Path semantic-commitlint > @commitlint/cli > @commitlint/load > lodash.merge
More info https://www.npmjs.com/advisories/1066
high Prototype Pollution
Package lodash.merge
Patched in >=4.6.2
Dependency of semantic-commitlint
Path semantic-commitlint > @commitlint/core > @commitlint/load > lodash.merge
More info https://www.npmjs.com/advisories/1066
high Prototype Pollution
Package lodash.merge
Patched in >=4.6.2
Dependency of semantic-commitlint
Path semantic-commitlint > @commitlint/cli > lodash.merge
More info https://www.npmjs.com/advisories/1066
high Prototype Pollution
Package lodash.mergewith
Patched in >=4.6.2
Dependency of semantic-commitlint
Path semantic-commitlint > @commitlint/cli > @commitlint/load > lodash.mergewith
More info https://www.npmjs.com/advisories/1071
high Prototype Pollution
Package lodash.mergewith
Patched in >=4.6.2
Dependency of semantic-commitlint
Path semantic-commitlint > @commitlint/core > @commitlint/load >
lodash.mergewith
More info https://www.npmjs.com/advisories/1071
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant