-
Notifications
You must be signed in to change notification settings - Fork 91
Open
Description
Description:
The stringify package in our repository is outdated, not utilized, and poses a potential security risk due to an identified vulnerability. Specifically, the package is no longer in use and contains a known vulnerability, the "kangax html-minifier REDoS vulnerability". This vulnerability, discovered in kangax html-minifier 4.0.0, exposes our system to Regular Expression Denial of Service (ReDoS) attacks via the candidate variable in htmlminifier.js.
Considering that the package serves no active purpose in our codebase and presents a security concern, it's imperative to remove it from the repository to mitigate any potential risks.
Action Plan:
- Removal of the
stringifyPackage:- We propose removing the
stringifypackage from this repository entirely. - This action will not impact any existing functionality as the package is not in use.
- We propose removing the
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels