The braces npm module is vulnerable to Regular Expression Denial of Service (ReDoS).
The braces module is a dependency of commitizen via
There is no new version of findup-sync or find-node-modules available that comes with a braces version >= 2.3.1 to fix the vulnerability.
I suggest using a package other than find-node-modules for the required functionality.
The
bracesnpm module is vulnerable to Regular Expression Denial of Service (ReDoS).The
bracesmodule is a dependency ofcommitizenviaThere is no new version of
findup-syncorfind-node-modulesavailable that comes with abracesversion >=2.3.1to fix the vulnerability.I suggest using a package other than
find-node-modulesfor the required functionality.