Closed edmund-oconnell closed 1 year ago
cssnano was previously replaced by @kaimi- with csso (see https://github.com/monzanifabio/cryptofont/pull/21) Is there any benefit in having clean-css over csso?
cssnano was previously replaced by @kaimi- with csso (see #21) Is there any benefit in having clean-css over csso?
No. The main thing was to address the vulnerabilities in the dependency chain of cssnano-cli. Looks like this is in hand so closing this PR.
Thanks for your contribution :)
Problem
Solution
The solution proposed is to swap out css-nano for clean-css. This package has 12m+ weekly downloads and is fully supported. More importantly it contains no vulnerable packages in its dependency chain