Skip to content

Fix cross-spawn high vulnerability#799

Merged
robinheinze merged 1 commit into
infinitered:masterfrom
Raiper34:fix/cross-spawn
Nov 24, 2025
Merged

Fix cross-spawn high vulnerability#799
robinheinze merged 1 commit into
infinitered:masterfrom
Raiper34:fix/cross-spawn

Conversation

@Raiper34

Copy link
Copy Markdown
Contributor

I have found, that cross-spawn got high vulnerability.

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ high          │ Regular Expression Denial of Service (ReDoS) in cross-spawn  │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ cross-spawn                                                  │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=7.0.5                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ cross-spawn                                                  │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ cross-spawn                                                  │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://www.npmjs.com/advisories/1104664                     │
└───────────────┴──────────────────────────────────────────────────────────────┘

This PR should fix it.

@robinheinze robinheinze merged commit 3fd896c into infinitered:master Nov 24, 2025
3 checks passed
infinitered-circleci pushed a commit that referenced this pull request Nov 24, 2025
## [5.2.2](v5.2.1...v5.2.2) (2025-11-24)

### Bug Fixes

* cross-spawn high vulnerability ([#799](#799)) ([3fd896c](3fd896c))
@infinitered-circleci

Copy link
Copy Markdown
Collaborator

🎉 This PR is included in version 5.2.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants