aquasecurity/cloudsploit

Update nodemon to v.2.0.20

nuhasha opened this issue · 0 comments

nodemon 1.3.5 - 2.0.16 || 2.0.18
Depends on vulnerable versions of chokidar 1.0.0-rc1 - 2.1.8 that depends on vulnerable versions of glob-parent
glob-parent before 5.1.2 vulnerable to Regular Expression Denial of Service in enclosure regex - GHSA-ww39-953v-wcq6
updating nodemon to v.2.0.20 will update its dependency chokidar and glob-parent