Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in optimist: consider replacing #28

Open
ngsctt opened this issue Dec 30, 2020 · 2 comments
Open

Vulnerability in optimist: consider replacing #28

ngsctt opened this issue Dec 30, 2020 · 2 comments

Comments

@ngsctt
Copy link

ngsctt commented Dec 30, 2020

I'm getting a dependabot alert for minimist < 0.2.1: CVE-2020-7598.

Currently, ejs-cli depends on optimist 0.6.1, which depends on minimist 0.0.10.

Optimist appears to have been abandoned, and has a deprecation notice directing users to yargs or nomnom.

You may want to consider replacing optimist with yargs. While it's not a trivial change, it doesn't look too complex — I made an attempt on a fork of this repository, but ejs-cli has stopped working in my project, so I can't test it properly.

@1000i100
Copy link
Contributor

1000i100 commented Jan 8, 2021

done 6 month ago in #26 but not merged. @fnobi are you still maintaining this repository ?

@1000i100
Copy link
Contributor

1000i100 commented Nov 8, 2021

Fixed in trunk b7ab39f
could be closed when ejs-cli 2.2.2 is published

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants