-
Notifications
You must be signed in to change notification settings - Fork 89
Open
Description
Hi, a vulnerability https://www.npmjs.com/advisories/1464 is introduced in selenium-cucumber-js via:
● [email protected] ➔ [email protected] ➔ [email protected] ➔ [email protected] ➔ [email protected]
phantomjs-prebuilt is a legacy package. It has not been maintained for about 3 years, and is not likely to be updated.
Is it possible to migrate phantomjs-prebuilt to other package to remediate this vulnerability?
I noticed several migration records for phantomjs-prebuilt in other js repos, such as
- in backstopjs, version 3.8.9 ➔ 3.9.0, remove phantomjs-prebuilt via commit
- in aegir, version 8.1.2 ➔ 9.0.0, remove phantomjs-prebuilt via commit
Are there any efforts planned that would remediate this vulnerability or migrate phantomjs-prebuilt?
Thanks
; )
Metadata
Metadata
Assignees
Labels
No labels