application-shell
application-shell copied to clipboard
Fix for the ReDOS vulnerability
application-shell is currently affected by the high-severity ReDOS vulnerability.
Vulnerable module: minimatch
Introduced through: browserify
This PR fixes the ReDoS vulnerability by upgrading browserify
to version 12.0.0 This upgrade will also fix the following other vulnerabilities:
-
Command Injection vulnerabilty in the
shell-quote
dependency.
Check out the Snyk test report to review other vulnerabilities that affect this repo.
- get alerts if newly disclosed vulnerabilities affect this repo in the future.
- generate pull requests with the fixes you want, or let us do the work: when a newly disclosed vulnerability affects you, we'll submit a fix to you right away.
Stay secure, The Snyk team
Thanks for your pull request. It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).
:memo: Please visit https://cla.developers.google.com/ to sign.
Once you've signed, please reply here (e.g. I signed it!
) and we'll verify. Thanks.
- If you've already signed a CLA, it's possible we don't have your GitHub username or you're using a different email address. Check your existing CLA data and verify that your email is set on your git commits.
- If you signed the CLA as a corporation, please let us know the company's name.