Skip to content
This repository has been archived by the owner on Sep 10, 2022. It is now read-only.

Fix for the ReDOS vulnerability #77

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-community
Copy link

application-shell is currently affected by the high-severity ReDOS vulnerability.

Vulnerable module: minimatch
Introduced through: browserify

This PR fixes the ReDoS vulnerability by upgrading browserify to version 12.0.0 This upgrade will also fix the following other vulnerabilities:

Check out the Snyk test report to review other vulnerabilities that affect this repo.

Watch the repo to

  • get alerts if newly disclosed vulnerabilities affect this repo in the future.
  • generate pull requests with the fixes you want, or let us do the work: when a newly disclosed vulnerability affects you, we'll submit a fix to you right away.

Stay secure,
The Snyk team

application-shell is currently affected by the high-severity [ReDOS vulnerability](https://snyk.io/vuln/npm:minimatch:20160620). 

Vulnerable module: `minimatch`
Introduced through: ` browserify`

This PR fixes the ReDoS vulnerability by upgrading `browserify` to version 12.0.0 This upgrade will also fix the following other vulnerabilities:
* [Command Injection vulnerabilty](https://snyk.io/vuln/npm:shell-quote:20160621) in the `shell-quote` dependency.


Check out the [Snyk test report](https://snyk.io/test/github/googlechrome/application-shell) to review other vulnerabilities that affect this repo. 

[Watch the repo](https://snyk.io/add) to 
* get alerts if newly disclosed vulnerabilities affect this repo in the future. 
* generate pull requests with the fixes you want, or let us do the work: when a newly disclosed vulnerability affects you, we'll submit a fix to you right away. 

Stay secure, 
The Snyk team
@googlebot
Copy link

Thanks for your pull request. It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

📝 Please visit https://cla.developers.google.com/ to sign.

Once you've signed, please reply here (e.g. I signed it!) and we'll verify. Thanks.


  • If you've already signed a CLA, it's possible we don't have your GitHub username or you're using a different email address. Check your existing CLA data and verify that your email is set on your git commits.
  • If you signed the CLA as a corporation, please let us know the company's name.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants