mapbox / node-pre-gyp

Node.js tool for easy binary deployment of C++ addons
BSD 3-Clause "New" or "Revised" License
1.11k stars 259 forks source link

Vulnerable dependency - Canvas #620

Closed guillaumearnx closed 2 years ago

guillaumearnx commented 2 years ago

Hello, someone tells me to open an issue here

Original link

I have an issue with node canvas and one of the collaborators replied that the problem could come from here

Thank's

springmeyer commented 2 years ago

Thanks for the heads up. I tried to create a dependabot PR for this, but it looks to be blocked on npmlog:

https://github.com/npm/npmlog/issues/85.

Screen Shot 2021-11-15 at 12 20 58 PM

fredkilbourn commented 2 years ago

@springmeyer this is actually coming from way upstream but the fix is making its way down. npmlog has a PR open right now that will update to gauge 4.0 which fixes this: https://github.com/npm/npmlog/pull/84

Keep an eye on it and we'll have a fix you can pull in soon.

fredkilbourn commented 2 years ago

@springmeyer npmlog v6 just published, should address the issue

springmeyer commented 2 years ago

Thanks. @mapbox/node-pre-gyp@1.0.7 is now published which includes npmlog@6