← All tasks
javascriptjsx-eslint/eslint-plugin-jsx-a11y #943Not a task: not reproduced

semver vulnerable to Regular Expression Denial of Service

envgap__jsx-eslint__eslint-plugin-jsx-a11y-943

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
5999555714f594c0fccfeeab2063c2658d9e4392
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

jsx-eslint/eslint-plugin-jsx-a11y #943 · read the original issue
The `semver` package has a security vulnerability. They only fixed v7, but the babel team has backported the fix to semver v6, can we use that? https://github.com/babel/babel/pull/15742



<details>

    <summary>npm audit output</summary>



```

# npm audit report



semver  <7.5.2

Severity: moderate

semver vulnerable to Regular Expression Denial of Service - https://github.com/advisories/GHSA-c2qf-rxjj-qqgw

fix available via `npm audit fix --force`

node_modules/eslint-plugin-jsx-a11y/node_modules/semver

  eslint-plugin-jsx-a11y  >=6.6.0

  Depends on vulnerable versions of semver

  node_modules/eslint-plugin-jsx-a11y

```

</details>
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]