Skip to content

Update dependency: solve security issue CVE-2021-3807#52

Open
magynhard wants to merge 1 commit intoheapwolf:masterfrom
magynhard:master
Open

Update dependency: solve security issue CVE-2021-3807#52
magynhard wants to merge 1 commit intoheapwolf:masterfrom
magynhard:master

Conversation

@magynhard
Copy link

The dependency strip-ansi 5.0.0 has another dependency that has a security issue.

By updating to strip-ansi 6.0.1 the coresponding dependency is updated as well.

Test is working fine with 6.0.1 but not 7.0.1, so i sticked to version 6.

Please bump the version and release a new npm version after accepting this pull request.

Security issue details:

image

CVE-2021-3807

@caub
Copy link

caub commented Feb 1, 2022

strip-ansi v7 is using ESM https://github.com/chalk/strip-ansi/releases/tag/v7.0.0, so yea good with ^6

@heapwolf can we merge this? do you want me to maintain this package btw?

@caub
Copy link

caub commented Feb 3, 2022

@davidmarkclements can we merge this please?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants