-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Bug] html-minifier high severity vulnerability #268
Comments
Thanks for the report ! Thanks again for you interest ! I will take a look at this in the few day and release a new minor version of this package 👍 |
Hi, thanks for that, i really appreciate your effort on maintaining this package, this has been very useful for me :D |
Hey @Tpleme, Thanks for your feedback ! And i'm glad that this package has been useful for you ! I just release |
Thank you very much. Really appreciate your time. Gonna close this. :P |
Describe the bug
A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0.
html-minifier
Additional context
A ReDos was found on this package, and it seems that they won't patch it, their last update was 5 years ago.
MJML lauched a alpha version replacing it with htmlnano and prettier (issue here).
The text was updated successfully, but these errors were encountered: