-
Notifications
You must be signed in to change notification settings - Fork 291
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Resolve security vulnerabilities in regex dependencies. #3154
Comments
Dismissed the alerts for now. I submitted them as issues to https://github.com/postcss/postcss-cli. The vulnerabilities are due to postcss-cli's dependencies. Everything else uses later versions of the regex packages. Options: 1) Since they're dev dependencies, ignore them for now until postcss-cli is updated or raises more problems, 2) remove dependencies from package.json and go back to manual installation. |
This issue isn't in postcss-cli, but in
Fortunately, this commit to hugo-extended removes the |
@jstirnaman - hey, were you able to test the updated hugo-extended? |
@jstirnaman if you are confident about your updates happy to accept a PR upstream in hugo-bin. Or if someone's up to it, pick up my patches and release scoped versions kevva/bin-wrapper#79 (comment) so that everyone benefits from it :) BTW I have a testing branch with my forks https://github.com/fenneclab/hugo-bin/tree/dev-packages which fixes all security vulns and slightly reduces the deps: main
dev-packages
|
Dependabot detected regex libraries with vulnerabilities. Update dependencies if possible.
The text was updated successfully, but these errors were encountered: