Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): pin colors package to 1.4.0 due to security vulnerability #3741

Merged
merged 2 commits into from
Jan 13, 2022

Conversation

sergei-startsev
Copy link
Contributor

@ellyxc
Copy link

ellyxc commented Jan 10, 2022

is it possible if we set in config color:false don't load/require the color to avoid similar issue in the future?

Copy link
Collaborator

@devoto13 devoto13 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR!

@sergei-startsev
Copy link
Contributor Author

is it possible if we set in config color:false don't load/require the color to avoid similar issue in the future?

I'd rather replace colors with another package (e.g. chalk) in the long run.

@simonl65
Copy link

Would be great if you would merge this - if only as a temporary workaround - as it's likely affecting MANY users worldwide ;-)

Happy for you to use an alternative, but delays cost lots of hair pulling.

@SerkanSipahi
Copy link

Here is an interim solution nrwl/nx#8450 (comment) !

@nicojs
Copy link
Contributor

nicojs commented Jan 11, 2022

Update: NPM has pulled versions 1.4.2 and 1.4.1. Installing the latest colors version will give you 1.4.0. This means that the problem is solved for karma users today, but this PR should still be merged IMO, for the karma users of tomorrow. (and later be replaced with a package that has a responsible maintainer)

@jginsburgn
Copy link
Member

@sergei-startsev please fix the CI tests :)

@jginsburgn
Copy link
Member

@sergei-startsev please fix the CI tests :)

Sorry, I just realized that CI will turn green after #3742 is merged. Let's just wait for that.

@jginsburgn jginsburgn merged commit a5219c5 into karma-runner:master Jan 13, 2022
@karmarunnerbot
Copy link
Member

馃帀 This PR is included in version 6.3.11 馃帀

The release is available on:

Your semantic-release bot 馃摝馃殌

@simonl65
Copy link

Thank you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

8 participants