GHSA-j9wj-m24m-7jj6: willitmerge has a Command Injection vulnerability
willitmerge describes itself as a command line tool to check if pull requests are mergeable. There is a Command Injection vulnerability in version willitmerge@0.2.1.
Resources:
- Project’s GitHub source code: https://github.com/shama/willitmerge/
- Project’s npm package: https://www.npmjs.com/package/willitmerge
References
Code Behaviors & Features
Detect and mitigate GHSA-j9wj-m24m-7jj6 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →