ember-learn / ember-cli-addon-docs-esdoc

MIT License
2 stars 6 forks source link

a vulnerability CVE-2021-33587 is introduced in ember-cli-addon-docs-esdoc #33

Open ayaka-kms opened 3 years ago

ayaka-kms commented 3 years ago

Hi, @rwwagner90, a vulnerability CVE-2021-33587 is introduced in ember-cli-addon-docs-esdoc via: ● ember-cli-addon-docs-esdoc@0.4.0 ➔ esdoc@1.1.0 ➔ cheerio@1.0.0-rc.2 ➔ css-select@1.2.0 ➔ css-what@2.1.3

However, esdoc is a legacy package, which has not been maintained for about 2 years. Is it possible to migrate esdoc to other package to remediate this vulnerability?

I noticed a migration record in other js repo for esdoc:

● in crest2d, version 1.1.2, migrated from esdoc to jsdoc via commit ● in wootils, version 3.0.4, migrated from esdoc to jsdoc via commit

Are there any efforts planned that would remediate this vulnerability or migrate esdoc?

Thanks.

RobbieTheWagner commented 3 years ago

@ayaka-kms this package is specifically for esdoc