Skip to content

Replace event-stream with something supported and secure #56

@jeremywadsack

Description

@jeremywadsack

As mentioned in #33 and addressed in #34 dominictarr/event-stream had a supply chain attack that infected a version of release. The solution was to pin to an older version. The author subsequently released a final version 4.0.1 which does not have the issue, however they stopped supporting the module in 2016 and there are suggestions of other packages here: dominictarr/event-stream#102 (comment). In 2018 the author archived the repo.

It would be great if ps-tree would be updated to depend on a library that is currently maintained for security.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions