Prerequisites
Description
minimatch package versions before 3.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS). Fixed version of minimatch (3.0.4) for mocha version 6.2.3 is causing cloud computing scans to fail.
In the past I've seen doing some upgrade for security reasons to older major versions so I wanted to know if I need to upgrade this service that is in maintenance mode or not. Thanks a lot in advance :)
Steps to Reproduce
N/A
Expected behavior: Security scans don't fail.
Actual behavior: N/A
Reproduces how often: 100%
Versions
- The output of
mocha --version and node_modules/.bin/mocha --version: 6.2.3
Prerequisites
faqlabelnode_modules/.bin/mocha --version(Local) andmocha --version(Global). We recommend that you not install Mocha globally.Description
minimatch package versions before 3.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS). Fixed version of minimatch (3.0.4) for mocha version 6.2.3 is causing cloud computing scans to fail.
In the past I've seen doing some upgrade for security reasons to older major versions so I wanted to know if I need to upgrade this service that is in maintenance mode or not. Thanks a lot in advance :)
Steps to Reproduce
N/A
Expected behavior: Security scans don't fail.
Actual behavior: N/A
Reproduces how often: 100%
Versions
mocha --versionandnode_modules/.bin/mocha --version: 6.2.3