moleculerjs / moleculer-repl

REPL module for Moleculer framework
http://moleculer.services/docs/moleculer-repl.html
MIT License
27 stars 25 forks source link

CVE advisory on dependencies #56

Closed shawnmcknight closed 2 years ago

shawnmcknight commented 2 years ago
λ npm audit
# npm audit report

ansi-regex  >2.1.1 <5.0.1
Severity: moderate
 Inefficient Regular Expression Complexity in chalk/ansi-regex - https://github.com/advisories/GHSA-93q8-gq69-wqmw
fix available via `npm audit fix --force`
Will install moleculer-repl@0.5.7, which is a breaking change
node_modules/@moleculer/vorpal/node_modules/ansi-regex
node_modules/inquirer/node_modules/ansi-regex
node_modules/log-update/node_modules/ansi-regex
  strip-ansi  4.0.0 - 5.2.0
  Depends on vulnerable versions of ansi-regex
  node_modules/@moleculer/vorpal/node_modules/strip-ansi
  node_modules/inquirer/node_modules/strip-ansi
  node_modules/log-update/node_modules/strip-ansi
    @moleculer/vorpal  *
    Depends on vulnerable versions of strip-ansi
    node_modules/@moleculer/vorpal
      moleculer-repl  >=0.6.0
      Depends on vulnerable versions of @moleculer/vorpal
      node_modules/moleculer-repl
    inquirer  3.2.0 - 7.0.4
    Depends on vulnerable versions of strip-ansi
    node_modules/inquirer
    string-width  2.1.0 - 4.1.0
    Depends on vulnerable versions of strip-ansi
    node_modules/log-update/node_modules/string-width
      wrap-ansi  3.0.0 - 6.1.0
      Depends on vulnerable versions of string-width
      Depends on vulnerable versions of strip-ansi
      node_modules/log-update/node_modules/wrap-ansi
        log-update  2.1.0 - 3.4.0
        Depends on vulnerable versions of wrap-ansi
        node_modules/log-update

Looks like some dependencies in @moleculerjs/vorpal are causing the issues.