yamlinc
yamlinc copied to clipboard
yamlinc depend on corrupts npm libs 'colors'
Run yamlinc with mess output after using npm install -g yamlinc to install globally
The infinite loop introduced in the code will keep running indefinitely; printing the gibberish non-ASCII character sequence endlessly on the console for any applications that use 'colors.'
More info about colors package issue is here: https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/
Temporary solution is to define exact version of package colors, i.e. 1.3.3 or 1.4.0 instead of ^1.3.3 (which install last minor/patch (compromised) version 1.4.2.
I've pushed pull request which fix this issue: https://github.com/javanile/yamlinc/pull/32
The compromised versions are deleted from npm.
There is no need to publish a new version of this library. Versions 1.4.1 and 1.4.2 are deleted, so this library uses last working colors package 1.4.0.
More info is here for example: https://github.com/Marak/colors.js/issues/317