Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CWE-772] Missing Release of Resource after Effective Lifetime #708

Closed
rudemex opened this issue Jan 18, 2024 · 1 comment
Closed

[CWE-772] Missing Release of Resource after Effective Lifetime #708

rudemex opened this issue Jan 18, 2024 · 1 comment
Labels
triage Investigation required

Comments

@rudemex
Copy link

rudemex commented Jan 18, 2024

The [email protected] dependency carries a vulnerability in the "inflight" dependency which is used by the "glob" dependency.

Missing Release of Resource after Effective Lifetime [Medium Severity][https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116] in [email protected] introduced by [email protected] > [email protected] > [email protected] > [email protected] > [email protected]

Here is the link to the analysis of this vulnerability
https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116

For the latest versions of these libraries, the affected dependency is no longer used, perhaps updating the dependencies will mitigate the vulnerability.

@cristianrgreco
Copy link
Collaborator

Thanks for raising @rudemex, I'm not seeing this issue from the Dependabot security scan or NPM audit logs

@cristianrgreco cristianrgreco added the triage Investigation required label Feb 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
triage Investigation required
Projects
None yet
Development

No branches or pull requests

2 participants