Update dependency for package pug to fix a vulnaribilty issue
VGalata opened this issue · 4 comments
VGalata commented
Package pug
has several versions affected by this vulnerability issue.
Are there plans to update the dependency to the next major version in the asciidoctor
package? The current version is ^2.0.4
(see here).
VGalata commented
Update: it seems to be addressed in #1689 though it uses only ^3.0.0
and the patched versions are 3.0.1
and 3.0.2
.
ggrossetie commented
Please note that Pug is included in the "all-in-one" package asciidoctor
but you can also use/install @asciidoctor/core
with your own version of Pug (if you are using it).
VGalata commented
Thank you, @ggrossetie! But, asciidoctor
is only a transitive dependency in our case.
ggrossetie commented
Should be fixed, the version in the package-lock.json is now 3.0.2