Dependabot/npm and yarn/cross spawn 7.0.6 #181
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This is a:
Description
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Open the app in your browser
It must've been deployed successfully.
Make sure everything works like before β no errors, crashes, or missing things
This update doesn't change anything you see; it just improves some background processes
Links
Link to the project board ticket: #1054
Link to initial: dependabot PR
Author checklist
qa
from a branch named<category>/<name>
, e.g.feature/edit-spaceships
orbugfix/restore-oxygen