-
Notifications
You must be signed in to change notification settings - Fork 279
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade ansi-regex dependency to address CVE-2021-3807 #949
Comments
@pzi Thanks for the heads up. We perform a security audit and address vulnerabilities typically once-per-release cycle. We'll make sure this one is addressed. In this case, it appears to be low risk since the affected module would only be used for development purposes. |
Ok, thanks for responding promptly and offering to fix it in the next release cycle. |
@pzi Starting from JSS 20 sitecore-jss-manifest is merged into sitecore-dev-tools, and these deps you mentioned are addressed. Some extra deps were addressed in dev too. |
Description
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3807
https://security.snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908
Expected behavior
No security issues.
Steps To Reproduce
Possible Fix
npm upgrade ansi-regex
Upgrade ansi-regex to version 6.0.1, 5.0.1 or higher.
Your Environment
The text was updated successfully, but these errors were encountered: