Update to strip-ansi@6.0.1 for ansi-regex CVE-2021-3807
envgap__yargs__cliui-111
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
57efcd2d1acdb0c8a6c9ee08f83719c0b60bf69b- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
yargs/cliui #111 · read the original issue
The latest version of cliui requires strip-ansi 6.0.0 which requires ansi-regex 5.0.0 which has a CVE against it: https://nvd.nist.gov/vuln/detail/CVE-2021-3807 Update the cliui dependency on strip-ansi to 6.0.1 which requires ansi-regex 5.0.1 to resolve the vulnerability in this dependency chain: https://github.com/chalk/strip-ansi/blob/v6.0.1/package.json#L47 I'm here because of this dependency chain: ``` ├─┬ @carbon/charts-vue@0.41.95 │ └─┬ @carbon/telemetry@0.0.0-alpha.6 │ └─┬ yargs@16.2.0 │ └─┬ cliui@7.0.4 │ └─┬ strip-ansi@6.0.0 │ └── ansi-regex@5.0.0 ``` Updating to the latest @carbon/charts-vue@0.41.95 does not resolve that issue. This may be related to issues #106 and #110.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]