Skip to content

[Security] cli-columns and cli-table3 have dependencies to vulnerable packages #3785

Description

@akaraman85

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

Security scans fail do to high warning of a security vulnerability in ansi-regex.

Expected Behavior

Security scan pass.

Steps To Reproduce

We use twistlock to do vulnerability detection, which relies on NVD to get vulnerability data.

The issue can be found here, https://nvd.nist.gov/vuln/detail/CVE-2021-3807 and here, https://snyk.io/vuln/npm:ansi-regex.

Environment

  • OS: Mac 11.5.2
  • Node: v12.21.0
  • npm: 7.21.1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Bugthing that needs fixingPriority 1high priority issueRelease 7.xwork is associated with a specific npm 7 releaseSecuritysecurity related

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions