Skip to content

cross-spawn Regular Expression Denial of Service (ReDoS) Snyk Vulnerability #11171

@KamilXu

Description

@KamilXu

Issue description

cross-spawn Regular Expression Denial of Service (ReDoS)

Expected Behavior

Typeorm should address snyk vulnerabilities

Actual Behavior

https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230

Steps to reproduce

Run snyk scan with typeorm

My Environment

Dependency Version
Operating System
Node.js version x.y.zzz
Typescript version x.y.zzz
TypeORM version x.y.zzz

Additional Context

No response

Relevant Database Driver(s)

  • aurora-mysql
  • aurora-postgres
  • better-sqlite3
  • cockroachdb
  • cordova
  • expo
  • mongodb
  • mysql
  • nativescript
  • oracle
  • postgres
  • react-native
  • sap
  • spanner
  • sqlite
  • sqlite-abstract
  • sqljs
  • sqlserver

Are you willing to resolve this issue by submitting a Pull Request?

No, I don’t have the time and I’m okay to wait for the community / maintainers to resolve this issue.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions