[Project board link](https://github.com/orgs/k8ssandra/projects/8/views/1?pane=issue&itemId=36182811) [NVD - CVE-2022-25883](https://nvd.nist.gov/vuln/detail/CVE-2022-25883) * versions of the semver package before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS). Reaper is taking a dependency on semver version 2.3.2 -> node_modules/bower/lib/node_module/semver/package.json Therefore, Reaper is vulnerable to CVE-2022-25883. The patch to fix this has been merged upstream in node-semver [v7](https://github.com/npm/node-semver/pull/564), [v6](https://github.com/npm/node-semver/pull/591) and [v5](https://github.com/npm/node-semver/pull/585). ┆Issue is synchronized with this [Jira Story](https://datastax.jira.com/browse/REAP-34) by [Unito](https://www.unito.io) ┆Issue Number: REAP-34