Skip to content

Commit

Permalink
fix: update to @dabh/colors for security vuln
Browse files Browse the repository at this point in the history
A Security Vuln was identified in the Colors package for >1.4.0, offending packages being `1.4.1`, `1.4.44-liberty`
- [source1](https://twitter.com/snyksec/status/1480286811482206216?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Etweet)
- [source2](https://twitter.com/snyksec/status/1480286811482206216?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Etweet)
- [source3](https://security.snyk.io/vuln/SNYK-JS-COLORS-2331906)

This PR updates the color package to using [@dabh/colors](https://www.npmjs.com/package/@dabh/colors) as stated on this [colors issue sintaxi#317](Marak/colors.js#317 (comment)) which is a safe alternative.
  • Loading branch information
mannyluvstacos authored Jan 13, 2022
1 parent 6128a96 commit 13dadb5
Showing 1 changed file with 3 additions and 2 deletions.
5 changes: 3 additions & 2 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,8 @@
"Jurgen Van de Moere <[email protected]>",
"Marco Emrich <[email protected]>",
"Roger K <[email protected]>",
"Claus Colloseus <[email protected]>"
"Claus Colloseus <[email protected]>",
"mannyluvstacos <[email protected]>"
],
"keywords": [
"static web server",
Expand All @@ -45,7 +46,7 @@
"async": "0.2.9",
"basic-auth": "^2.0.1",
"boxt": "^1.0.0",
"colors": "^1.4.0",
"@dabh/colors": "^1.4.0",
"connect": "^3.6.6",
"envy-json": "0.2.1",
"fs-extra": "1.x",
Expand Down

0 comments on commit 13dadb5

Please sign in to comment.