ember-learn / ember-learn/ember-cli-addon-docs-esdoc
a vulnerability CVE-2021-33587 is introduced in ember-cli-addon-docs-esdoc
- Dominant language
- JavaScript
- Stars
- 2
- Forks
- 4
- PR merge metrics
- No merged PRs in 30d
Description
Hi, @rwwagner90, a vulnerability CVE-2021-33587 is introduced in ember-cli-addon-docs-esdoc via:
● ember-cli-addon-docs-esdoc@0.4.0 ➔ esdoc@1.1.0 ➔ cheerio@1.0.0-rc.2 ➔ css-select@1.2.0 ➔ css-what@2.1.3
However, **esdoc** is a legacy package, which has not been maintained for about 2 years.
Is it possible to migrate **esdoc** to other package to remediate this vulnerability?
I noticed a migration record in other js repo for **esdoc**:
● in crest2d, version 1.1.2, migrated from esdoc to jsdoc via [commit](https://github.com/danielwedding/Crest2D/commit/21f81271dfce002fac02e7d45cab2427ecfc25be)
● in wootils, version 3.0.4, migrated from esdoc to jsdoc via [commit](https://github.com/homer0/wootils/commit/65ab6cdaa69b79fca64efc6af458a5ae4d662661)
Are there any efforts planned that would remediate this vulnerability or migrate **esdoc**?
Thanks.
Contributor guide
Assessment
This issue has not been assessed yet.