npm audit fails on @octokit dependencies #34283
-
How are you running Renovate?Self-hosted Renovate If you're self-hosting Renovate, tell us which platform (GitHub, GitLab, etc) and which version of Renovate.GitHub Please tell us more about your question or problemHi. When running Would it be possible to update these dependencies? (see the log below for pointers). Thanks. Logs (if relevant)Logs
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 9 replies
-
The only production place used is this:
Which is only used to fetch OSV files from GitHub. I don't see how this could potentially be exploitable, unless github.com or perhaps the OSV project were compromised and added a ReDoS attack. If either were compromised, we have bigger problems than a ReDoS |
Beta Was this translation helpful? Give feedback.
Looks like it's fixed by 39.175.5 after #34307