You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As the author of the original qrcode dependency currently has no time to release a fixed version, I forked [2] the qrcode lib and bumped the dependency to a fixed version [3].
angularx-qrcode 13.0.3 was released today with a fork of the lib, which makes no use of the affected colors.js versions.
The dependency will be switched back the moment there is a fix released.
Cordobo
changed the title
fix: release version without affected colors.js version
Fixed version without corrupted colors.js version released
Jan 12, 2022
The underlying lib
qrcode
has a dependency of the libcolors.js
which was corrupted on purpose by its author [1]. Read the article Dev corrupts NPM libs 'colors' and 'faker' breaking thousands of apps by BleepingComputer.As the author of the original
qrcode
dependency currently has no time to release a fixed version, I forked [2] the qrcode lib and bumped the dependency to a fixed version [3].[1] colors.js
https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/
[2] The used fork is located here:
https://github.com/Cordobo/node-qrcode
[3] Commit changes
Cordobo/node-qrcode@e09bcd3
The text was updated successfully, but these errors were encountered: