Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NPM release to resolve security vulnerability #29

Closed
cdrini opened this issue Nov 14, 2019 · 4 comments · Fixed by #37
Closed

NPM release to resolve security vulnerability #29

cdrini opened this issue Nov 14, 2019 · 4 comments · Fixed by #37

Comments

@cdrini
Copy link

cdrini commented Nov 14, 2019

The version of the clean-css dependency has been updated to a safe version, but the version of less-plugin-clean-css on npm is outdated and doesn't have the fix. Could we release a new version on npm?

wmfgerrit pushed a commit to wikimedia/mediawiki-services-mobileapps that referenced this issue Nov 21, 2019
With this change, all current potential vulnerabilities are resolved,
except for one, which is blocked on the package maintainers publishing a
new version with the fix.[1]

Removed many `eslint-disable` directives which were rendered unnecessary
and now cause lint warnings and errors due to eslint config changes.

[1] less/less-plugin-clean-css#29

Change-Id: Ifc6cb7f0d590c02bfa0b1bf6f1b379a497b11daa
@thesocialdev
Copy link

+1

@ZLevine
Copy link

ZLevine commented Dec 5, 2019

Yes, please publish the latest version—I can't use this library because we need clean-css V4.

@BasixKOR
Copy link

BasixKOR commented Jan 4, 2020

Any news on this?

@thesocialdev
Copy link

Just FYI, we couldn't wait for this to be published and published in our org. See https://www.npmjs.com/package/@wikimedia/less-plugin-clean-css

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants