From 321b23eebb818787482f4d733f5cdcc1af29a1d5 Mon Sep 17 00:00:00 2001 From: billchurch Date: Tue, 26 Sep 2017 11:37:42 -0400 Subject: [PATCH] Revert to debug@2.6.9 to eliminate ReDoS in %o formatter --- ChangeLog.md | 3 +++ package.json | 2 +- 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/ChangeLog.md b/ChangeLog.md index 0f7d700..1ec3dde 100644 --- a/ChangeLog.md +++ b/ChangeLog.md @@ -1,4 +1,7 @@ # Change Log +## [0.1.3] TBD +### Changed +- Revert to debug@2.6.9 to eliminate ReDoS in %o formatter ## [0.1.2] 2017-07-31 ### Added - ssh.readyTimeout option in config.json (time in ms, default 20000, 20sec) diff --git a/package.json b/package.json index c855f9c..1767d15 100644 --- a/package.json +++ b/package.json @@ -29,7 +29,7 @@ "dependencies": { "basic-auth": "^1.1.0", "colors": "^1.1.2", - "debug": "^3.0.0", + "debug": "^2.6.9", "express": "^4.15.4", "express-session": "^1.15.5", "morgan": "^1.8.2",