Chore: update semver to fix CVE-2022-25883 #6927
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I have read the CONTRIBUTING docs and I saw this Dependency part. Opened this PR since the vuln is pretty old and wasn't yet fixed, might have been overlooked?
Updated semver from 5.7.1 to version 5.7.2. (also other deps got updated). [email protected] is vulnerable to CVE-2022-25883
I'm using [email protected] and it pulls [email protected] which is [vulnerable](CVE-2022-25883](https://nvd.nist.gov/vuln/detail/CVE-2022-2588). Cannot override the transitive because npm is a bundled package. Ran
npm update semver
to get it updated to 5.7.2.I might choose the wrong branch for this, please guide me to the correct one