Skip to content

Update version of html-minifier-terser dependency#1761

Open
bradentg wants to merge 1 commit intojantimon:mainfrom
bradentg:update-html-minifier-terser
Open

Update version of html-minifier-terser dependency#1761
bradentg wants to merge 1 commit intojantimon:mainfrom
bradentg:update-html-minifier-terser

Conversation

@bradentg
Copy link
Copy Markdown

Current version of html-minifier-terser depends on outdated version of terser vulnerable to ReDOS.
html-minifier-terser@7.0.0 depends on terser ^5.14.2, which addresses the vulnerability.

@nksfrank
Copy link
Copy Markdown

can we get this security vulnerability fix released?

@hawkril
Copy link
Copy Markdown

hawkril commented Sep 19, 2022

Would be great if @jantimon or @mastilver Could take a look so this vulnerability fix can be merged and released. Thank you!

@imki123
Copy link
Copy Markdown

imki123 commented Oct 26, 2022

I have solved this issue. There are some cached codes in a lock file. Remove lock file and node_modules. Then install them, and compare lock files.
FYI. webpack/webpack#16306 (comment)

@boroth
Copy link
Copy Markdown

boroth commented Mar 22, 2024

Any updates? Still getting dependabot vulnerability alerts because of this dependency :(

Copy link
Copy Markdown

@DharanBro DharanBro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why there is no change in lock file?

@stale
Copy link
Copy Markdown

stale bot commented Jan 2, 2026

This issue had no activity for at least half a year. It's subject to automatic issue closing if there is no activity in the next 15 days.

@stale stale bot added the wontfix label Jan 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants