Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Security: Vulnerable dependency [email protected] [SNYK-JS-MINIMATCH-15309438, CVE-2026-26996]

オープン
#792 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
38/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
javascript
領域
security

調査の方向性

[email protected] の依存関係ツリーを調査し、broccoli-plugin、walk-sync、rimraf、glob、および関連パッケージを通る記載されたパスを追跡します。すべての minimatch のバージョンが 10.2.1 以上に解決されることを確認してから、プロジェクトに既存のテストスイートを実行します。依存関係の互換性を損なうことなく、脆弱な minimatch のバージョンが残っていなければ完了です。

索引モデルが issue の本文から書いたものです。

説明

Summary

[email protected] depends on multiple vulnerable versions of minimatch (3.1.2, 9.0.5), which are vulnerable to Regular Expression Denial of Service (ReDoS) (High severity).

Vulnerability Details

Affected versions of minimatch are vulnerable to ReDoS in the AST class, caused by catastrophic backtracking when an input string contains many * characters in a row followed by an unmatched character.

Example Affected Dependency Paths

minimatch is pulled in through multiple paths in [email protected]:

# Dependency Path
1 ember-cli-htmlbars → [email protected] → [email protected] → [email protected]
2 ember-cli-htmlbars → [email protected] → [email protected] → [email protected] → [email protected]
3 ember-cli-htmlbars → [email protected] → [email protected] → [email protected] → [email protected]
4 ember-cli-htmlbars → [email protected] → [email protected] → [email protected] → [email protected] → [email protected]
few more...

Potential Remediation

  1. Fix has been given in minimatch to version 10.2.1 or higher. Upgrade transitive dependencies that pull in vulnerable minimatch versions — particularly broccoli-plugin, broccoli-persistent-filter, broccoli-debug, walk-sync, rimraf, and glob — to versions that depend on minimatch@>=10.2.1

References

主要言語
JavaScript
スター
77
フォーク
65
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

ember-cli/ember-cli-htmlbars のほかの issue

ember-cli/ember-cli-htmlbars の issue をすべて見る

似ている issue

JavaScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。