-
Notifications
You must be signed in to change notification settings - Fork 29
Open
Description
nugget's dependencies contain pretty-bytes "^1.0.2" which is a legacy package, pretty-bytes's dependencies contain meow "^3.1.0", meow's dependencies contain trim-newlines "^1.0.0" which is vulnerable. the trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the .end() method. you'd better upgrade pretty-bytes
Details: GHSA-7p7h-4mm5-852v
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels