Dependencies need to be upgraded for security purposes
Closed this issue · 1 comments
jakobjohansson commented
Dependencies need to be upgraded for security purposes. From dependabot audits:
@bugsnag/source-maps@2.3.1 requires semver@2 || 3 || 4 || 5 via a transitive dependency on normalize-package-data@2.5.0
The alert explains further:
Versions of the package semver before 7.5.2 on the 7.x branch, before 6.3.1 on the 6.x branch, and all other versions before 5.7.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
mclack commented
Thanks for bringing this to our attention.
This has now been addressed in the bugsnag-source-maps v2.3.2 release.