Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

This package relies on vulnerable dependencies #9

Closed
stof opened this issue Sep 22, 2021 · 0 comments · Fixed by #10
Closed

This package relies on vulnerable dependencies #9

stof opened this issue Sep 22, 2021 · 0 comments · Fixed by #10

Comments

@stof
Copy link

stof commented Sep 22, 2021

The package currently depends on v2 of string-width, which transitively depend on ansi-regex v3, for which Snyk reports a ReDoS vulnerability.

It would be great to upgrade to the v4 of string-width, which uses a version of ansi-regex that has been patched (upgrading to string-width v5 is harder, as it is an ES module and so might require migrating to ESM too, which would require a major version, which then would still justify upgrading to v4 first to fix things in the existing major version)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant