-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Vulnerability in node-sass > sass-graph > yargs > cliui > strip-ansi > ansi-regex #3190
Comments
Upgrading |
@alexarsh I had the same issue today. After a lot of trial and error I finally noticed this error message:
So I ran |
@katannshaw Hi. Tried updating to v14, but still have the same version dependency |
Looks like xzyfer/sass-graph is abandoned, the last release is almost 1,5 years ago, and the PR to fix this vulnerability has been open for 15 days now. As node-sass is deprecated we took the time to move to dart-sass. I suggest everyone else that runs into this issue to do the same. |
For many projects dart-sass is substantially slower so is not a viable solution in a lot of cases. In some of our foundation-sites projects the incremental compilation moves from 5 seconds to approximately 5 minutes or longer. There is a new dart VM hosted compilation module in the works but its still very much experimental and no webpack integration yet. Possibly the best approach is to absorb sass-graph module into node-sass in its current state and then update the dependencies in node-sass accordingly? Would allow node-sass to remain in maintenance mode successfully for a while until the other options mentioned above are available. |
Any updates on this? Has any work been done to absorb sass-graph into node-sass as suggested in the previous post? |
I opened #3202 to absorb sass-graph as suggested, but the maintainers haven't responded anything yet. not sure what else I can do... |
|
[email protected] has been released with a patch for this. |
Fixed in 7.0.1. |
npm -v
): 6.14.15node -v
): v14.18.0node -p process.versions
):{
node: '14.18.0',
v8: '8.4.371.23-node.84',
uv: '1.42.0',
zlib: '1.2.11',
brotli: '1.0.9',
ares: '1.17.2',
modules: '83',
nghttp2: '1.42.0',
napi: '8',
llhttp: '2.1.3',
openssl: '1.1.1l',
cldr: '39.0',
icu: '69.1',
tz: '2021a',
unicode: '13.0'
}
node -p process.platform
): darwinnode -p process.arch
): x64node -p "require('node-sass').info"
):node-sass 6.0.1 (Wrapper) [JavaScript]
libsass 3.5.5 (Sass Compiler) [C/C++]
npm ls node-sass
): [email protected]There is the following dependencies tree:
─┬ [email protected]
│ └─┬ [email protected]
│ └─┬ [email protected]
│ ├─┬ [email protected]
│ │ ├─┬ [email protected]
│ │ │ └── [email protected]
When [email protected] have the following vulnerability issues:
https://snyk.io/vuln/npm:[email protected]
Is there a chance that [email protected] dependency can be updated in order to fix the issue?
The text was updated successfully, but these errors were encountered: