Skip to content

First use question: npq i npq #201

Answered by lirantal
baruchiro asked this question in Q&A
Discussion options

You must be logged in to vote

The public test page doesn't show indirect vulnerabilities, which npq has if you test it with Snyk:

❯ snyk test npq@2.0.23

Testing npq@2.0.23...

✗ High severity vulnerability found in ansi-regex
  Description: Regular Expression Denial of Service (ReDoS)
  Info: https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
  Introduced through: listr@0.14.3
  From: listr@0.14.3 > listr-update-renderer@0.5.0 > log-update@2.3.0 > wrap-ansi@3.0.1 > strip-ansi@4.0.0 > ansi-regex@3.0.0
  From: listr@0.14.3 > listr-update-renderer@0.5.0 > log-update@2.3.0 > wrap-ansi@3.0.1 > string-width@2.1.1 > strip-ansi@4.0.0 > ansi-regex@3.0.0


Project path:      npq@2.0.23

Tested npq@2.0.23 for known vulnerabilities,…

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@baruchiro
Comment options

@lirantal
Comment options

@baruchiro
Comment options

@lirantal
Comment options

Answer selected by baruchiro
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants