Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update editorconfig package #2160

Closed
k725 opened this issue Jun 23, 2023 · 4 comments
Closed

Update editorconfig package #2160

k725 opened this issue Jun 23, 2023 · 4 comments

Comments

@k725
Copy link

k725 commented Jun 23, 2023

The editorconfig package that js-beautify depends 1 on is too old and contains a vulnerable package (semver). 23
I hope you will consider updating the editorconfig package.

At least the latest version of the editorconfig package 4 does not contain the vulnerable semver package.

Footnotes

  1. https://github.com/beautify-web/js-beautify/blob/main/package.json#L53

  2. https://security.snyk.io/package/npm/semver

  3. https://github.com/advisories/GHSA-c2qf-rxjj-qqgw

  4. https://github.com/editorconfig/editorconfig-core-js/blob/main/package.json#L46

@bitwiseman
Copy link
Member

#2161 Fixes.

@curtispd
Copy link

curtispd commented Jul 7, 2023

Could we get a release for this please so that we can resolve the underlying vulnerability?

@curtispd
Copy link

@bitwiseman would it be possible to create a release with this change ? We have strict compliance timelines to remediate CVEs in our apps and this would really help us out

@bitwiseman
Copy link
Member

@curtispd I'll get to it in the next few days.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants