jondot / hygen

The simple, fast, and scalable code generator that lives in your project.
http://www.hygen.io
MIT License
5.65k stars 253 forks source link

Noticed security issue async #392

Closed JackHowa closed 2 years ago

JackHowa commented 2 years ago

Saw the nested alert with the vulnerability to async. https://github.com/advisories/GHSA-fwr7-v2mv-hh25

Let me know if any one else is looking to potentially update before spelunking


Looks like the relevant issue may be with ejs and potentially unneeded dep https://github.com/mde/ejs/issues/659

JackHowa commented 2 years ago

@jondot appreciate your work on hygen -- saves us loads of time. Let me know if you have time to go over a quick deps fix for a security warning https://github.com/jondot/hygen/pull/394

JackHowa commented 2 years ago

@jondot let me know if this is a concern. thanks for the time!

JackHowa commented 2 years ago

Closed as will not fix