Skip to content

Conversation

@j9t
Copy link

@j9t j9t commented Oct 17, 2024

Bumped up bin-version-* packages to their latest versions, as the currently used versions are vulnerable to ReDos attacks due to the their dated import of find-versions. This is to also enable fixes for upstream packages like gifsicle.

This is a basic update likely warranting attention from someone who knows the project. When running the tests, these threw the same errors after as they did before the update.

j9t added 2 commits October 17, 2024 15:00
Renamed 'bin-check' to 'binary-check' and 'bin-version-check' to 'binary-version-check'. Also updated their respective version numbers in package.json.

(This commit message was AI-generated.)

Signed-off-by: Jens Oliver Meiert <[email protected]>
Updated the package version from 4.1.0 to 4.1.1 to include recent fixes and improvements. This ensures users have the latest stable release.

(This commit message was AI-generated.)

Signed-off-by: Jens Oliver Meiert <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant