question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Backport of security patch, for benefit of yargs

See original GitHub issue

I know it’s a pain in the neck, but would you consider back-porting https://github.com/chalk/ansi-regex/pull/37 to the 5.x.x release line, for the benefit of yargs.

Yargs is making the effort during the transition to ESM to support both CJS and ESM, which makes us unable to update to the latest version of string-width.

If you were willing to make an exception (I know you’re pushing folks towards using ESM exclusively) it would be really valuable for yargs users using CJK character sets.

Issue Analytics

  • State:closed
  • Created 2 years ago
  • Comments:30 (14 by maintainers)

github_iconTop GitHub Comments

5reactions
cardilcommented, Sep 21, 2021

GitHub Advisory Database still lists this package as affected for <6.0.1, here: https://github.com/advisories/GHSA-93q8-gq69-wqmw

Anyone knows how to update that information as well?

This page https://docs.github.com/en/code-security/security-advisories/creating-a-security-advisory suggest the repo owner should be able to edit this information.

4reactions
sindresorhuscommented, Sep 16, 2021

The range in the report says <5.0.1 but it has not been proven that all versions below 5.0.0 are vulnerable. (Snyk: You should generally not just assume all previous versions are affected by default).

Read more comments on GitHub >

github_iconTop Results From Across the Web

Backporting Security Patches of Web Applications: - USENIX
In this paper, we design a security patch backporting frame- work and implement a prototype on injection vulnerability patches, called SKYPORT.
Read more >
Security Backporting Practice - Red Hat Customer Portal
For most products, our default practice is to backport security fixes, but we do sometimes provide version updates for some packages after careful...
Read more >
Maintainers Should Consider Following Node.js' Release ...
It offers significant benefits to the community for library maintainers to follow this ... ensuring the ability to take security patches.
Read more >
Inspections - Automattic/jetpack - Measure and Improve Code ...
Branch: update/backport-jp-10.0-changelog ... fix/do-not-display-security-dev-mode · update/deploy-to-master-stable · fix/apps-landing-images ...
Read more >
Blog Archives - Page 20 of 24 - OpenJS Foundation
ensuring the ability to take security patches. reducing the burden on maintainers. allowing module authors to take advantage of new platform features sooner ......
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found