prettier-eslint
prettier-eslint copied to clipboard
Audit Fail due to an used package
Versions:
-
prettier-eslint
version: 13.0.0 -
node
version: 12.14.1
Problem description: Audit is failing due to package used pretty-format
data:image/s3,"s3://crabby-images/0eae0/0eae011dda828b87abd0a52aaf213c40711eef3e" alt="Screenshot 2021-10-13 at 4 12 26 AM"
Suggested solution: update package.json
The earliest patched version of ansi-regex
is 5.0.1
. This is fixed in pretty-format
>= 25.1.0
(which requires ansi-regex ^5.0.0
).
Any updates on this? My CICD is failing because of this issue.
In the meantime, my team has been using https://github.com/IBM/audit-ci. The tool allows us to continue auditing our dependencies as part of our CICD pipeline, but we can allow certain advisories so they don't cause the pipeline to fail.
My company is ALSO concerned about this vulnerability. Is it possible to switch to using something other than the now archived loglevel-colored-level-prefix
tool that is locked in on a very old chalk
?
@kentcdodds do you know of an alternative to your now archived loglevel-colored-level-prefix
library that I can use to make a PR to remove this issue?
I'm afraid no.
@kentcdodds would it be worth converting this over to using Chalk? Or maybe removing this package and functionality so it will not have a color? I'm happy to do this if you would like.
Stale issue