Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update strip-ansi due to security vulnerability about ansi-regex(v4.1.0) #1506

Closed
jcoyne opened this issue Nov 15, 2021 · 5 comments
Closed

Comments

@jcoyne
Copy link

jcoyne commented Nov 15, 2021

Description

The cli package specifies strip-ansi 5.2.0. This version pulls in a vulnerable version of ansi-regex. Can strip-ansi be upgraded to 6.x or 7.x?

https://github.com/react-native-community/cli/blob/master/packages/cli/package.json#L55

See:

@thymikee
Copy link
Member

Feel free to submit a PR with a fix. I'd be happy to merge it :)

@jcoyne
Copy link
Author

jcoyne commented Nov 15, 2021

@thymikee I don't actually use react-native, it only ended up in my bundle by way of a indirect dependency (aws-amplify/amplify-js#9119). So, while I can make this change. I have no way of testing that it still works.

@Brma1048
Copy link

Brma1048 commented Mar 25, 2022

Any updates on this? It's still using 4.1.0 with security vulnerability
and ora and ws must also be updatet to a newer version

@github-actions
Copy link

There hasn't been any activity on this issue in the past 3 months, so it has been marked as stale and it will be closed automatically if no further activity occurs in the next 7 days.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants