Skip to content

Update version of html-minifier-terser dependency#1761

Open
bradentg wants to merge 1 commit into
jantimon:mainfrom
bradentg:update-html-minifier-terser
Open

Update version of html-minifier-terser dependency#1761
bradentg wants to merge 1 commit into
jantimon:mainfrom
bradentg:update-html-minifier-terser

Conversation

@bradentg

Copy link
Copy Markdown

Current version of html-minifier-terser depends on outdated version of terser vulnerable to ReDOS.
html-minifier-terser@7.0.0 depends on terser ^5.14.2, which addresses the vulnerability.

@nksfrank

Copy link
Copy Markdown

can we get this security vulnerability fix released?

@hawkril

hawkril commented Sep 19, 2022

Copy link
Copy Markdown

Would be great if @jantimon or @mastilver Could take a look so this vulnerability fix can be merged and released. Thank you!

@imki123

imki123 commented Oct 26, 2022

Copy link
Copy Markdown

I have solved this issue. There are some cached codes in a lock file. Remove lock file and node_modules. Then install them, and compare lock files.
FYI. webpack/webpack#16306 (comment)

@boroth

boroth commented Mar 22, 2024

Copy link
Copy Markdown

Any updates? Still getting dependabot vulnerability alerts because of this dependency :(

@DharanBro DharanBro left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why there is no change in lock file?

@stale

stale Bot commented Jan 2, 2026

Copy link
Copy Markdown

This issue had no activity for at least half a year. It's subject to automatic issue closing if there is no activity in the next 15 days.

@stale stale Bot added the wontfix label Jan 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants