Node-sass: libsass 3.6

Created on 4 Jun 2019  ·  14Comments  ·  Source: sass/node-sass

Most helpful comment

Is there any update on this?

All 14 comments

https://github.com/sass/libsass/releases/tag/3.6.1

I forked node-sass to integrate the latest libsass 3.6.1 commit #2b8a17a, mocha tests fail, but it does build successfully, and I'm able to use new libsass features like @content arguments. https://github.com/sass/node-sass/pull/2714

Is adding support for 3.6 anywhere on the roadmap?

It's a decent amount of work so it'll happen when I have a couple free days
to build the binaries.

On Thu., 25 Jul. 2019, 11:38 pm Dylan Copeland, notifications@github.com
wrote:

Is adding support for 3.6 anywhere on the roadmap?


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
https://github.com/sass/node-sass/issues/2685?email_source=notifications&email_token=AAENSWAVZZIS6JUVLOCIJLDQBGUFHA5CNFSM4HSWRSKKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD2ZP4TA#issuecomment-515046988,
or mute the thread
https://github.com/notifications/unsubscribe-auth/AAENSWBQE7HWWI2B3ZFTTALQBGUFHANCNFSM4HSWRSKA
.

libsass contains a HIGH severity vulnerability that is fixed in 3.6.0
https://nvd.nist.gov/vuln/detail/CVE-2018-19827
https://github.com/sass/libsass/commit/b21fb9f84096d9927780b86fa90629a096af358d

Can you provide a timeline for the update?

libsass 3.6.0 also contains a fantastic bug fix sass/libsass#2849 that fixes some Windows specific compilation errors.

And it implements passing arguments to content blocks, which is super useful. https://sass-lang.com/documentation/at-rules/mixin#passing-arguments-to-content-blocks

Is there any update on this?

PR with upgrade is kinda waiting for several months, already ↪️ https://github.com/sass/node-sass/pull/2714

PR with upgrade is kinda waiting for several months, already arrow_right_hook #2714

Does not seem that way to me, sorry!

@xzyfer @nschonni What do you think about producing a 4.x release with libsass 3.6.x? ah, we can't due to https://github.com/sass/libsass/issues/2611

Is this happing any time soon? I'm looking forward to mixin content block arguemnts.
Thanks for making an maintaining this wonderful library <3

image
As per Azure Dev Ops report, libsass contains a HIGH severity vulnerability that is fixed in 3.6.0
Please can you provide timeline for the update?

@karthikrajthandapani this is a volunteer-run project, so no timelines are provided. Sorry.

This will land in 5.0. follow the open pr for updates.

On Wed, 30 Oct 2019, 10:48 pm Marcin Cieślak, notifications@github.com
wrote:

@karthikrajthandapani https://github.com/karthikrajthandapani this is a
volunteer-run project, so no timelines are provided. Sorry.


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
https://github.com/sass/node-sass/issues/2685?email_source=notifications&email_token=AAENSWGPJZ5UDHS44O7UNXLQRFYALA5CNFSM4HSWRSKKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOECT3YSI#issuecomment-547863625,
or unsubscribe
https://github.com/notifications/unsubscribe-auth/AAENSWAVMSIRXWII6LOD6ADQRFYALANCNFSM4HSWRSKA
.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

harukaeru picture harukaeru  ·  3Comments

nagyfej picture nagyfej  ·  3Comments

bgolubovic picture bgolubovic  ·  3Comments

primiano picture primiano  ·  3Comments

goseesomething picture goseesomething  ·  3Comments