You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ansi-regex used in cliui, wrap-ansi , npm-normalize-package-bin, and yargs module is vulnerable to CVE-2021-3807. This vulenrability is resolved in ansi-regex 6.0.1 and 5.0.1. Is it possible to package either 6.0.1 or 5.0.1 in the upcoming buildpack release.?
The text was updated successfully, but these errors were encountered:
ansi-regex is not directly packaged in this buildpack. It's an indirect dependency coming from the npm tool.
Unless npm updates its ansi-regex, there’s nothing we can do - which I don’t believe npm has done yet. See link.
Issue: npm/cli#3785
ansi-regex used in cliui, wrap-ansi , npm-normalize-package-bin, and yargs module is vulnerable to CVE-2021-3807. This vulenrability is resolved in ansi-regex 6.0.1 and 5.0.1. Is it possible to package either 6.0.1 or 5.0.1 in the upcoming buildpack release.?
The text was updated successfully, but these errors were encountered: