Unmaintained dependency (istanbuljs) & security vulnerabilities? #3786
-
It seems like instanbuljs is not actively being maintained. There is at least one dependency to the Any advice on working around this security issue in the depedency? |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
You could use your package manager to override this dependency's version. E.g. Note that the My personal opinion is that these ReDoS vulnerabilities are mostly just noise in NPM ecosystem - especially in tooling related packages. In this case the practical issue you could run is that your coverage report generation could be slower if someone already had access on your machine/CI and exploited the vulnerability. |
Beta Was this translation helpful? Give feedback.
-
Istanbul packages have now released new versions. However we'll need to release new version of |
Beta Was this translation helpful? Give feedback.
Istanbul packages have now released new versions. However we'll need to release new version of
@vitest/coverage-istanbul
: #3814