Skip to content

fix: Upgrade semver to fix ReDoS vulnerability#11596

Merged
anthonyshew merged 2 commits intomainfrom
fix/TURBO-5140-semver-redos
Jan 31, 2026
Merged

fix: Upgrade semver to fix ReDoS vulnerability#11596
anthonyshew merged 2 commits intomainfrom
fix/TURBO-5140-semver-redos

Conversation

@anthonyshew
Copy link
Copy Markdown
Contributor

Summary

  • Upgrades root semver dependency from 7.5.0 to 7.5.2 to fix a high severity ReDoS vulnerability

Vulnerability Details

Package: semver >=7.0.0 <7.5.2
Issue: Regular Expression Denial of Service (ReDoS)
Severity: High
Reference: TURBO-5140

The semver package versions prior to 7.5.2 are vulnerable to ReDoS attacks due to inefficient regex patterns when parsing version strings.

Testing

  • pnpm install completes successfully
  • Lockfile updated to use semver 7.5.2

@vercel
Copy link
Copy Markdown
Contributor

vercel Bot commented Jan 31, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
examples-basic-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
examples-designsystem-docs Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
examples-gatsby-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
examples-kitchensink-blog Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
examples-nonmonorepo Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
examples-svelte-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
examples-tailwind-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
examples-vite-web Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
turbo-site Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm
turborepo-test-coverage Ready Ready Preview, Comment, Open in v0 Jan 31, 2026 9:34pm

@github-actions
Copy link
Copy Markdown
Contributor

Coverage Report

Metric Coverage
Lines 75.88%
Functions 46.75%
Branches 0.00%

View full report

@anthonyshew anthonyshew merged commit df27a84 into main Jan 31, 2026
47 checks passed
@anthonyshew anthonyshew deleted the fix/TURBO-5140-semver-redos branch January 31, 2026 21:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant