Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency: solve security issue CVE-2021-3807 #52

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

magynhard
Copy link

The dependency strip-ansi 5.0.0 has another dependency that has a security issue.

By updating to strip-ansi 6.0.1 the coresponding dependency is updated as well.

Test is working fine with 6.0.1 but not 7.0.1, so i sticked to version 6.

Please bump the version and release a new npm version after accepting this pull request.

Security issue details:

image

CVE-2021-3807

@caub
Copy link

caub commented Feb 1, 2022

strip-ansi v7 is using ESM https://github.com/chalk/strip-ansi/releases/tag/v7.0.0, so yea good with ^6

@heapwolf can we merge this? do you want me to maintain this package btw?

@caub
Copy link

caub commented Feb 3, 2022

@davidmarkclements can we merge this please?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants