You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Like most CVEs, it's a false positive. We're not using new Range nor are we doing anything that wouldn't be a self-attack (ie, not an attack).
We can't ever bump the semver version because v7 drops support for engines we support, so unless the fix is backported to v6, it'll just have to remain a false positive. However, the semver team is indeed backporting it to v6, so you don't have to do anything but wait.
@ljharb thanks for the explanation and sorry for the duplicate issue. I didn't see an open issue for this but it didn't occur to me to check the closed issues filter.
Recently NPM started showing this vulnerability report for libraries that use old versions of
semver
.The text was updated successfully, but these errors were encountered: