Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

yargs-parser vulnerabilities #108

Closed
akoushke opened this issue May 1, 2020 · 5 comments · Fixed by #111
Closed

yargs-parser vulnerabilities #108

akoushke opened this issue May 1, 2020 · 5 comments · Fixed by #111

Comments

@akoushke
Copy link

akoushke commented May 1, 2020

can you please update your packages?
02_11_59

help a homie out :)

@ruettenm
Copy link

ruettenm commented May 4, 2020

Would be great to get a fix soon 👍

@thomas-mcdonald
Copy link

hey @xzyfer - I see node-sass attempts to keep a huge amount of node backcompat but there are no patched versions of yargs with explicit support for < node 4.

I feel I've been staring at different version specifiers and dependency trees for so long I'm not sure of the best way forward. A possible option would be to split the cli-part of this repo out from the API? It seems there is no requirement to push yargs as a dependency down the tree for consumers that are only using this as an API.

@xzyfer
Copy link
Owner

xzyfer commented May 4, 2020

Hey @thomas-mcdonald I've been giving this some thought also, hence the delayed patch. As you've said node-sass maintains BC back node 0.10 - however it does not utilise the sass-graph cli.

I have considered splitting out the cli function as you've also suggested but have decided against creating more ongoing work for myself. I think in this case we're ok to just bump the yargs dep. Node-sass BC should be fine since we shouldn't be excerising the yargs code paths.

@xzyfer
Copy link
Owner

xzyfer commented May 4, 2020

Note well also want to bump yargs dependency on the V2 branch since that's the version line node-sass currently uses

xzyfer added a commit that referenced this issue May 4, 2020
xzyfer added a commit that referenced this issue May 4, 2020
@xzyfer
Copy link
Owner

xzyfer commented May 4, 2020

Released as 3.0.5 and 2.2.5

nashiko pushed a commit to nashiko/js-graph-dependency that referenced this issue Mar 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants