sergi/jsftp

Debug package Regex DOS vulnerability

walshie4 opened this issue · 1 comments

https://nodesecurity.io/advisories/534

As per the linked advisory the debug package has a regex DOS vulnerability which is resolved by updating to v2.6.9. Looks like y'all use ^ ranged versions so this should just be a simple update & publish to fix the warning.

sergi commented

Done, thanks.