node-corporal icon indicating copy to clipboard operation
node-corporal copied to clipboard

Removed optimist - no longer supported and has vulnerabilities

Open jriffel opened this issue 4 years ago • 0 comments

The package optimist is no longer maintained and is has dependencies with known vulnerabilities. Several pull requests have been sent to optimist over the last couple of years but the project is completely dormant without a code update in 6 years. I looked at the use of optimist and felt it could be removed fairly easily. Please consider this pull request to remove optimist and thus eliminate the child dependencies with known vulnerabilities. Thanks.

jriffel avatar Feb 02 '22 21:02 jriffel