Skip to content

Security: diff dependency vulnerable to DoS (GHSA-73rr-hh4g-fpgx) #252

@jashan777

Description

@jashan777

Description

Hi,
I noticed that uvu depends on the diff package with the version range: "diff": "^5.0.0"
A recent GitHub Security Advisory reports a Denial of Service vulnerability in diff < 8.0.3
GHSA-73rr-hh4g-fpgx
the above issue is now being flagged by npm audit and other dependency security scanners for projects that depend on uvu.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions