browserify/static-eval

CVE in word-wrap

SymbioticKilla opened this issue · 1 comments

Hi @goto-bus-stop ,

there is a CVE in word-wrap: jonschlinkert/word-wrap#33
It is fixed and integrated in latest optionator 0.9.x, which is used in escodegen 2.x.
Is there any chance to update escodegen to 2.x?
Thanks!

escodegen@1.14.3
│ └─┬ optionator@0.8.3
│ └── word-wrap@1.2.3

Optionator team will not merge the fix to 0.8.x: gkz/optionator#46

I just opened #43 for this.