neoss
neoss copied to clipboard
[Snyk] Upgrade ansi-regex from 6.0.1 to 6.1.0
Snyk has created this PR to upgrade ansi-regex from 6.0.1 to 6.1.0.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
-
The recommended version is 1 version ahead of your current version.
-
The recommended version was released on 22 days ago.
Release notes
Package name: ansi-regex
- 6.1.0 - 2024-09-09
-
6.0.1 - 2021-09-10
Fixes
- Fix ReDoS in certain cases (#37)
You are only really affected if you run the regex on untrusted user input in a server context, which it's very unlikely anyone is doing, since this regex is mainly used in command-line tools.
Thank you @ yetingli for the patch and reproduction case!
- Fix ReDoS in certain cases (#37)
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: