You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
dependency-cruiser 8.0.2 depends on [email protected] which depends on optimist@^0.6.1 which depends on a vulnerable version of [email protected].*.
Currently there is no new handlebars version available that does not produce vulnerability errors, but there already is an open ticket for that: handlebars-lang/handlebars.js#1658
Once there is a new handlebars version available, please update the dependency on handlebars in dependency cruiser. Or, maybe even better, change the dependency right away to a semantic version range like ^4.7.3.
The text was updated successfully, but these errors were encountered:
B.t.w. on runtime dependency-cruiser does not use handlebars' cli, so strictly speaking it's a false positive (as it is for most installations using handlebars, I guess).
I have a strict policy to not trust semantic version ranges of third party packages beyond what
I can run on a ci. As in normal circumstances dependency-cruiser gets updated every one
or two weeks (which includes updates to external dependencies) and faster in case of
security issues this should be good enough to go.
dependency-cruiser 8.0.2 depends on
[email protected]
which depends onoptimist@^0.6.1
which depends on a vulnerable version of[email protected].*
.Currently there is no new handlebars version available that does not produce vulnerability errors, but there already is an open ticket for that: handlebars-lang/handlebars.js#1658
Once there is a new handlebars version available, please update the dependency on
handlebars
in dependency cruiser. Or, maybe even better, change the dependency right away to a semantic version range like^4.7.3
.The text was updated successfully, but these errors were encountered: