gluegun icon indicating copy to clipboard operation
gluegun copied to clipboard

fix(deps): bump ejs to 3.1.8

Open bennetthardwick opened this issue 3 years ago • 3 comments

Currently when installing a CLI created with gluegun users will see a message saying "1 critical severity vulnerability" because of a vulnerability in ejs: https://github.com/advisories/GHSA-phwq-j96m-2c2q

1661753952

While it's not likely this will cause an issue it might worry some people who install gluegun created CLIs.

This vulnerability is patched in [email protected] so bumping the version will get rid of this message.

bennetthardwick avatar Aug 29 '22 06:08 bennetthardwick

@jamonholmgren we'll want to get this merged soon as it resolves issues on a freshly spun-up project.

yulolimum-capture-2022-09-03--19-43-33

yulolimum avatar Sep 04 '22 02:09 yulolimum

If possible, update ejs to version 3.1.7 or higher as it is causing problems with windows powershell, by default powershell blocks execution of dependencies that have vulnerability and using script to bypass execution of vulnerable dependencies is not good for system security. thanks for the attention and compression 💜 unknown

ravenastar-js avatar Sep 07 '22 23:09 ravenastar-js

Looking to see if we can get this merged and closed as well. We've got some workarounds in place but are looking forward to getting the vulnerability properly addressed. Thanks!

ThomasDRT avatar Sep 21 '22 17:09 ThomasDRT

Same here. Awaiting the fix for this vulnerability as well. Thanks much in advance!

Mashbourne1 avatar Oct 06 '22 16:10 Mashbourne1

while ejs is no longer a dependency, the change to ts-node resolves this issue for me, thanks

danstepanov avatar Jun 13 '23 01:06 danstepanov

Hey everyone, sorry about the long delay on this. Finally getting to cleanup of all PRs and issues.

jamonholmgren avatar Sep 28 '23 17:09 jamonholmgren

:tada: This PR is included in version 5.1.6 :tada:

The release is available on:

Your semantic-release bot :package::rocket:

infinitered-circleci avatar Sep 28 '23 21:09 infinitered-circleci