Skip to content

Vulnerability issues in dependant package meow@3.7.0 #95

Description

@guidocecilio

Hi,
The current version is using meow@3.7.0 which at the same time is dependant on trim-newlines@1.0.0 is having a High vulnerability issue. It would be nice to bump a new release using meow@10.1.1 to fix that vulnerability.

meow@10.1.1 using trim-newlines@^4.0.2
https://github.com/sindresorhus/meow/blob/main/package.json#L54

High Regular Expression Denial of Service in trim-newlines
Package trim-newlines
Patched in >=3.0.1
Dependency of @wdio/devtools-service [dev]
Path @wdio/devtools-service > speedline > meow > trim-newlines

More info GHSA-7p7h-4mm5-852v

Thanks,
Guido.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions