millermedeiros / esformatter

ECMAScript code beautifier/formatter
MIT License
970 stars 91 forks source link

Bump `debug`. #473

Open wtgtybhertgeghgtwtg opened 7 years ago

wtgtybhertgeghgtwtg commented 7 years ago

esformatter depends on debug@0.7.4. It also depends on rocambole-whitespace@1.0.0, which depends on debug@2.3.3. So two versions of debug are packaged with esformatter. I can create a pull request if you would like.

zkuzmic commented 5 years ago

Another reason to do this is because npm audit show the following issue:

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Low           │ Regular Expression Denial of Service                         │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ debug                                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >= 2.6.9 < 3.0.0 || >= 3.1.0                                 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ esformatter [dev]                                            │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ esformatter > debug                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/534                             │
└───────────────┴──────────────────────────────────────────────────────────────┘

It'd be great to update debug to a version in the range above.