Closed bodograumann closed 2 years ago
You have included colors@^1.1.2 as dependency, which would install version 1.4.1. This dependency contains an intentional DoS. Please pin to version 1.4.0.
colors@^1.1.2
1.4.1
1.4.0
For background: https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/
Seems there are already some pull-requests. Nice :-)
i merged #473 to use chalk instead. thanks @bodograumann @yedidyak @imnotjames for your quick response to this issue!
published 0.13.1
You have included
colors@^1.1.2
as dependency, which would install version1.4.1
. This dependency contains an intentional DoS. Please pin to version1.4.0
.For background: https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/