autodesk-forks / MaterialX

MaterialX C++ and Python libraries
http://www.materialx.org/
Apache License 2.0
107 stars 23 forks source link

Fix security issues with JsMaterialXView #1304

Closed bernardkwok closed 3 years ago

bernardkwok commented 3 years ago

Issues found in package-lock.json for JsMaterialView. Snapshot shown here be present by examining this repo. image https://github.com/autodesk-forks/MaterialX/security/dependabot

Note: Any dependence on Autodesk internal artifacts should also be removed if possible when this is cleaned up. We are currently dependent art-bobcat for instance.

bernardkwok commented 3 years ago

Appears ansi-html can be replaced by ansi-html-community ? (https://www.npmjs.com/package/ansi-html-community).