Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue with Minimatch (Update Minimatch) #4840

Closed
4 tasks done
asilluron opened this issue Mar 8, 2022 · 0 comments · Fixed by #4843
Closed
4 tasks done

Security Issue with Minimatch (Update Minimatch) #4840

asilluron opened this issue Mar 8, 2022 · 0 comments · Fixed by #4843
Labels
dependencies Pull requests that update a dependency file

Comments

@asilluron
Copy link

Prerequisites

  • Checked that your issue hasn't already been filed by cross-referencing issues with the faq label
  • Checked next-gen ES issues and syntax problems by using the same environment and/or transpiler configuration without Mocha to ensure it isn't just a feature that actually isn't supported in the environment in question or a bug in your code.
  • 'Smoke tested' the code to be tested by running it outside the real test suite to get a better sense of whether the problem is in the code under test, your usage of Mocha, or Mocha itself
  • Ensured that there is no discrepancy between the locally and globally installed versions of Mocha. You can find them with: node_modules/.bin/mocha --version(Local) and mocha --version(Global). We recommend that you not install Mocha globally.

Description

Mocha depends on minimatch which includes a security vulnerability described here

Steps to Reproduce

N/A

Expected behavior:
Passes security scans (Prisma Cloud)

Actual behavior:
Fails security scans

Reproduces how often: [What percentage of the time does it reproduce?]
100%

Versions

All

Additional Information

https://huntr.dev/bounties/e4e1393c-d590-4492-9f43-8be3f3321629/
isaacs/minimatch#146

@juergba juergba added dependencies Pull requests that update a dependency file and removed unconfirmed-bug labels Mar 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants