bem / html-differ

Сompares two HTML
http://bem.info/tools/testing/html-differ/
MIT License
211 stars 44 forks source link

Insecure dependencies #155

Closed UziTech closed 5 years ago

UziTech commented 6 years ago

Are there any plans to update the insecure dependencies or is this repo unmaintained?

/cc @alexbaumgertner, @arikon, @awinogradov, @belozer, @blond, @dfilatov, @dosyara, @eGavr, @gela, @incrop, @indutny, @levonet, @mishaberezin, @mishanga, @narqo, @SevInf, @tadatuta, @tavriaforever, @tormozz48, @varya, @veged, @vithar, @voischev, @yarastqt, @Yeti, @zxqfox

alexbaumgertner commented 6 years ago

At least lodash will update in https://github.com/bem/html-differ/pull/147.

Unfortunately I'm not a maintainer. @eGavr could you help?

badamo37 commented 5 years ago

I'm assuming nothing ever came of this? html-differ has a few failed audits thanks to out of date/insecure dependencies still.

UziTech commented 5 years ago

I don't believe this repo is maintained anymore. We ended up forking it and updating it ourselves.

badamo37 commented 5 years ago

Kinda figured this was the case. Noticed there's been a PR to update the lodash vulnerability for...almost 2 years now. We'll have to do the same as you then! Thanks!

tadatuta commented 5 years ago

Just merged https://github.com/bem/html-differ/pull/147 and https://github.com/bem/html-differ/pull/158/

tadatuta commented 5 years ago

html-differ@1.4.0 released

badamo37 commented 5 years ago

Awesome, thank you!!