Skip to content

Transitive dependency: diff@8.0.2 DoS fix available upstream #5657

@thomasturrell

Description

@thomasturrell

Following on from #5607.

There is a published security advisory for diff:
GHSA-73rr-hh4g-fpgx (DoS in parsePatch via crafted input)

The issue is fixed upstream in jsdiff PR #649 and released in diff@>=8.0.3:

Mocha currently appears to resolve diff@8.0.2, so this is just to flag that a fixed version is available upstream if/when you’re next updating this dependency.

I appreciate this is likely low severity in practice, but it does surface in audit tooling and CI.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions