Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-4068: High vulnerability found in @stoplight/spectral-cli version 6.11.1 #2639

Open
rushikeshchoche opened this issue Jun 11, 2024 · 1 comment
Labels
jira p/high t/bug Something isn't working triaged

Comments

@rushikeshchoche
Copy link

rushikeshchoche commented Jun 11, 2024

The current version of @stoplight/spectral-cli (6.11.1) seems to have a known vulnerability linked to it. The issue is associated with the braces package, specifically versions prior to 3.0.3. More details can be found in the following advisory: [GHSA-grv7-fg5c-xmjg]

Addressing this vulnerability will not only secure @stoplight/spectral-cli but also benefit other packages that depend on it. Your assistance in resolving this issue would be greatly appreciated. Thank you!

@daniel-white daniel-white added t/bug Something isn't working p/high triaged jira labels Jun 14, 2024
Copy link
Contributor

This ticket has been labeled jira. A tracking ticket in Stoplight's Jira (STOP-648) has been created.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
jira p/high t/bug Something isn't working triaged
Projects
None yet
Development

No branches or pull requests

2 participants