paambaati/codeclimate-action

View on GitHub
package-lock.json

Summary

Maintainability
Test Coverage

marked Regular Expression Denial of Service
Invalid

        "marked": {
            "version": "4.1.1",
            "resolved": "https://registry.npmjs.org/marked/-/marked-4.1.1.tgz",
            "integrity": "sha512-0cNMnTcUJPxbA6uWmCmjWz4NJRe/0Xfk2NhXCUHjew9qJzFN20krFnsUe7QynwqOwa5m1fZ4UDg0ycKFVC0ccw==",
            "dev": true,
Severity: Minor
Found in package-lock.json by nodesecurity

Regular Expression Denial of Service

Overview:

The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can block for around 6 seconds.

Recommendation:

Consider another markdown parser until the issue can be addressed.

There are no issues that match your filters.

Category
Status