istanbuljs / nyc

the Istanbul command line interface
https://istanbul.js.org/
ISC License
5.55k stars 353 forks source link

ansi-regex@5.0.0 Vulnerability within nyc@15.1.0 #1509

Open gamboaa opened 1 year ago

gamboaa commented 1 year ago

nyc has the following dependency tree

nyc@15.1.0 └─┬ yargs@15.4.1 └─┬ cliui@6.0.0 └─┬ strip-ansi@6.0.0 └── ansi-regex@5.0.0

ansi-regex@5.0.0 has a vulnerability

Classname: CVE-2021-3807 System output: {{

{ "message": "cvssV3: HIGH, score: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)" } }}