[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Status of texinfo/js/yarn.lock ?
From: |
Hilmar Preuße |
Subject: |
Status of texinfo/js/yarn.lock ? |
Date: |
Sun, 13 Nov 2022 10:22:23 +0100 |
User-agent: |
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Thunderbird/102.4.2 |
Hi,
hopefully this is not a FAQ, but I found nothing in the archive.
What is the status of the code sitting in subdir "js"? To me this code
looks quite unmaintained. I'm just asking, b/c the dependabot [1]
reports a lot of vulnerabilities in js/yarn.lock. I'm aware that the are
mostly sitting in external referenced modules.
Could you clarify, what the strategy for this piece of code is? Many thanks!
Hilmar
[1] https://github.com/debian-tex/texinfo/security/dependabot
--
sigfault