semver vulnerable to Regular Expression Denial of Service
envgap__jsx-eslint__eslint-plugin-jsx-a11y-943
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
5999555714f594c0fccfeeab2063c2658d9e4392- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
jsx-eslint/eslint-plugin-jsx-a11y #943 · read the original issue
The `semver` package has a security vulnerability. They only fixed v7, but the babel team has backported the fix to semver v6, can we use that? https://github.com/babel/babel/pull/15742
<details>
<summary>npm audit output</summary>
```
# npm audit report
semver <7.5.2
Severity: moderate
semver vulnerable to Regular Expression Denial of Service - https://github.com/advisories/GHSA-c2qf-rxjj-qqgw
fix available via `npm audit fix --force`
node_modules/eslint-plugin-jsx-a11y/node_modules/semver
eslint-plugin-jsx-a11y >=6.6.0
Depends on vulnerable versions of semver
node_modules/eslint-plugin-jsx-a11y
```
</details>04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]