Skip to content

Update rimraf (CWE-772) #506

@w3nl

Description

@w3nl
  • Version: 20.10.0
  • Platform: Linux tux 6.5.0-14-generic #14-Ubuntu SMP PREEMPT_DYNAMIC Tue Nov 14 14:59:49 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux (Ubuntu 23.10)

Rimraf is outdated, and because C8 use an old version, we receive vulnerability issues.
Inflight has a CWE issue, that is an indirect dependency of this package.

rimraf@3.0.2 › glob@7.2.3 › inflight@1.0.6

https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
https://cwe.mitre.org/data/definitions/772.html

In rimraf 4 this is already solved, by removing glob as a dependency:
https://github.com/isaacs/rimraf/blob/main/CHANGELOG.md

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions