Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: replace ansi-html with ansi-html-community to fix vulnerability #413

Merged
merged 2 commits into from
Sep 13, 2021

Conversation

nttibbetts
Copy link
Contributor

This PR contains a:

  • bugfix
  • new feature
  • code refactor
  • test update
  • typo fix
  • metadata update

Motivation / Use-Case

This is a fix for the vulnerability reported in CVE-2021-23424 by
replacing the ansi-html dependency with a fork of the project that has
the suggested fix and resolves #412

This is a fix for the vulnerability reported in [CVE-2021-23424][CVE] by
replacing the ansi-html dependency with a fork of the project that has
the [suggested fix][ansi-html-fix] and resolves [webpack-contrib#412][412]

[CVE]: https://nvd.nist.gov/vuln/detail/CVE-2021-23424
[ansi-html-fix]: Tjatse/ansi-html#19
[412]: webpack-contrib#412
@linux-foundation-easycla
Copy link

linux-foundation-easycla bot commented Sep 9, 2021

CLA Signed

The committers are authorized under a signed CLA.

@glenjamin glenjamin merged commit 3d5018a into webpack-contrib:master Sep 13, 2021
@glenjamin
Copy link
Collaborator

Released in 2.25.1 - thanks for the PR!

@nttibbetts nttibbetts deleted the replace-ansi-html branch September 14, 2021 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

ReDoS Vulnerability
2 participants