Skip to content

Conversation

@appakz
Copy link
Collaborator

@appakz appakz commented Dec 21, 2021

This is a stop-gap measure to patch a known vulnerability with the version of three we currently use in bootstrap. We'll work on updating and using the latest publicly-available version once we have time to deal with the breaking changes it brings with it.

@rockhymas @jameswelle I created an articulate branch on this fork that points to the release tag for the version we currently use, and opened this PR against that branch. This just applies the updated regular expressions to patch the vulnerability. We'll update our package reference in bootstrap to consume this package directly from the resulting commit on the articulate branch after merging this.

This is a stop-gap measure to patch a known vulnerability with the version of three we currently use in bootstrap. We'll work on updating and using the latest publicly-available version once we have time to deal with the breaking changes it brings with it.
@appakz appakz changed the title Apply regex change to address DOS vulnerability Apply regex change to address DoS vulnerability Dec 21, 2021
@appakz appakz merged commit be94337 into articulate Dec 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants