Replacement of listr with a maintained library? #108
Replies: 1 comment 1 reply
-
Hey, could you please be more specific about how this vulnerability could actually be abused? npm's auditing is very noisy, and a lot of times the vulnerability is irrelevant to the project, because either it's a dev dependency, or the vulnerable part of the API isn't even used in the project. I haven't had any issues with |
Beta Was this translation helpful? Give feedback.
-
Listr seems to no longer be being maintained and there's a vulnerability in a nested dependency that's used in several places - ansi-regex (see GHSA-93q8-gq69-wqmw). Is there any intention to replace this with a different library that's being maintained? listr2 appears to be a maintained replacement, though I haven't tested it myself.
Beta Was this translation helpful? Give feedback.
All reactions