Latest yargs has nested ansi-regex vulnerability
envgap__yargs__yargs-2240
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
394f5f86d15a9bb319276518d36cb560d7cb6322- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
yargs/yargs #2240 · read the original issue
Dependency Hierarchy:
yargs-17.5.1.tgz (Root Library)
- cliui-7.0.4.tgz
- strip-ansi-6.0.0.tgz
- ❌ ansi-regex-5.0.0.tgz (Vulnerable Library)
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]