a vulnerability CVE-2021-33587 is introduced in arcads
ayaka-kms opened this issue · 0 comments
ayaka-kms commented
Hi, @nealmalkaniwapo, a vulnerability CVE-2021-33587 is introduced in arcads via:
● arcads@4.0.1 ➔ esdoc@1.1.0 ➔ cheerio@1.0.0-rc.2 ➔ css-select@1.2.0 ➔ css-what@2.1.3
However, esdoc is a legacy package, which has not been maintained for about 2 years.
Is it possible to migrate esdoc to other package to remediate this vulnerability?
I noticed a migration record in other js repo for esdoc:
● in crest2d, version 1.1.2, migrated from esdoc to jsdoc via commit
● in wootils, version 3.0.4, migrated from esdoc to jsdoc via commit
Are there any efforts planned that would remediate this vulnerability or migrate esdoc?
Thanks.