Mocha: address npm audit fixes

Created on 31 Mar 2019  路  7Comments  路  Source: mochajs/mocha

Greetings folks! The js-yaml issue addressed here is causing us a bit of grief with our vulnerability checks in the Google npm modules. Thank you so much for the quick fix. Would it be possible to cut a patch release with the change so npm audit stops poking us? Thank you!

security

Most helpful comment

Seconded, it's a bit of a pain in our CI as well.

All 7 comments

cc @bcoe @ofrobots

Seconded, it's a bit of a pain in our CI as well.

As far as I know, a new release is blocked by https://github.com/mochajs/mocha/milestone/27 I'm basing this on an explanation from @boneskull in https://gitter.im/mochajs/contributors. Relevant messages start March 18th.

In particular, discussion on https://github.com/mochajs/mocha/pull/3829 has stalled.
There's a simpler fix proposed in https://github.com/mochajs/mocha/pull/3823, pending approval by the maintainers. (I submitted it, so it's the one issue I've been following)

sorry been busy w other work. will try to look into it this week

@boneskull thank you!

isaacs mentioned that tap-yaml or yaml would possibly be suitable replacements for js-yaml fwiw

@boneskull thank you \o/ totally understand being busy.

Was this page helpful?
0 / 5 - 0 ratings