Skip to content

Uncontrolled resource consumption in braces - https://github.com/advisories/GHSA-grv7-fg5c-xmjg #248

@fabianszabo

Description

@fabianszabo

I guess this is an issue with tailwindcss rather than this package? But I still wanted to mention it.

# npm audit report

braces  <3.0.3
Severity: high
Uncontrolled resource consumption in braces - https://github.com/advisories/GHSA-grv7-fg5c-xmjg

npm ls braces prints this:

└─┬ tailwindcss-elevation@2.0.0
  └─┬ tailwindcss@3.4.4
    ├─┬ chokidar@3.5.3
    │ └── braces@3.0.2
    └─┬ micromatch@4.0.5
      └── braces@3.0.2 deduped

npm explain braces prints this:

braces@3.0.2 dev peer
node_modules/braces
  braces@"~3.0.2" from chokidar@3.5.3
  node_modules/chokidar
    chokidar@"^3.5.3" from tailwindcss@3.4.4
    node_modules/tailwindcss
      peer tailwindcss@"^3.0.1" from tailwindcss-elevation@2.0.0
      node_modules/tailwindcss-elevation
        dev tailwindcss-elevation@"^2.0.0" from the root project
  braces@"^3.0.2" from micromatch@4.0.5
  node_modules/micromatch
    micromatch@"^4.0.4" from fast-glob@3.3.2
    node_modules/fast-glob
      fast-glob@"^3.3.0" from tailwindcss@3.4.4
      node_modules/tailwindcss
        peer tailwindcss@"^3.0.1" from tailwindcss-elevation@2.0.0
        node_modules/tailwindcss-elevation
          dev tailwindcss-elevation@"^2.0.0" from the root project
    micromatch@"^4.0.5" from tailwindcss@3.4.4
    node_modules/tailwindcss
      peer tailwindcss@"^3.0.1" from tailwindcss-elevation@2.0.0
      node_modules/tailwindcss-elevation
        dev tailwindcss-elevation@"^2.0.0" from the root project

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions