Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Update fileset dependency per https://nodesecurity.io/advisories/118 #653

Closed
ntwb opened this issue Jun 24, 2016 · 8 comments
Closed

Update fileset dependency per https://nodesecurity.io/advisories/118 #653

ntwb opened this issue Jun 24, 2016 · 8 comments

Comments

@ntwb
Copy link

ntwb commented Jun 24, 2016

The minimatch NPM module has been patched due to a regular expression denial of service:

Once this is merged and a new release of fileset is released then a pull request can be created

@ntwb
Copy link
Author

ntwb commented Jun 27, 2016

Fileset 2.0.2 has now been released with this minimatch dependency update:

mklabs/node-fileset@v1.0.1...v2.0.2

@use-strict
Copy link

Any updates here?

@ghost
Copy link

ghost commented Jul 13, 2016

Hi, is there any news on this?

@austinnichols101
Copy link

Bump.

@gotwarlost
Copy link
Owner

I've not had time to take a look and it is not a simple update since one of the tests fail and I need to figure out why. Will get to it soon,

@popomore
Copy link
Contributor

popomore commented Jul 28, 2016

fileset has always ignored node_modules mklabs/node-fileset@c6593c0

So this testcase failed.

@jonfreedman
Copy link

+1

@maxkoryukov
Copy link

Looks, like there is an overall solution: #673

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants