Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable Package Dependency: minimatch #352

Closed
pamo opened this issue Jul 10, 2016 · 2 comments
Closed

Vulnerable Package Dependency: minimatch #352

pamo opened this issue Jul 10, 2016 · 2 comments

Comments

@pamo
Copy link
Contributor

pamo commented Jul 10, 2016

Ran snyk on my blog and found a vulnerable dependency in Gatsby.

Regular Expression Denial of Service

Snyk Details

Introduced through: likescoffee@pamo/pamo.github.io#384dbb3717fb6bf07c2f693dc5b0ad8eac19893a › [email protected][email protected][email protected][email protected][email protected][email protected][email protected][email protected]

@pamo
Copy link
Contributor Author

pamo commented Jul 10, 2016

Seems like it would be on the contributors of postcss-import to update 😞

@KyleAMathews
Copy link
Contributor

Hey @pamo — thanks for raising this issue. This shouldn't be a problem though for your blog or Gatsby sites in general as minimatch code is only run by Gatsby while developing so safely protected from any malicious actors. I don't recommend exposing a Gatsby development server to the public generally speaking. This is one of the great things about static sites is that they're just files, so not an attack vector.

And yes — postcss-import would need to apply the update for this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants