-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Labels
Status: PR WelcomeWelcome to Pull RequestWelcome to Pull Requestgood first issueGood for newcomersGood for newcomershelp wantedExtra attention is neededExtra attention is needed
Description
chrono-node CVE-2021-23371: https://snyk.io/vuln/SNYK-JS-CHRONONODE-1083228
I would like to update chrono-node to v2.2.4 or higher, due to a vulnerability about a DoS attack issue.
Chrono-node v2 has breaking changes, which is critical for this textlint rule.
For Users
- Chrono’s default now handles only international English. While in the previous version, it tried to parse with all known languages.
- The current fully supported languages are
en,ja, andfr(deandptare partially supported). Other languages from v1 (nlandzh) are under development.
https://github.com/wanasit/chrono#whats-changed-in-the-v2
So, following things have to be done to update chrono-node to v2.x:
- Change the code to use the chrono-node v2.x correctly with locale support.
- Drop the support for
es(Spanish) that is not supported by chrono-node v2.x. - (Possibly) Drop the support for auto language detection and user will have to choose a language in textlintrc file.
(If you find it's not necessary, it's fine to just close this issue.)
(一旦Issueを立てましたが、必要ないようであればそのまま閉じていただいて構いません。)
docwhat, massongit, tyler36 and atm-snag2
Metadata
Metadata
Assignees
Labels
Status: PR WelcomeWelcome to Pull RequestWelcome to Pull Requestgood first issueGood for newcomersGood for newcomershelp wantedExtra attention is neededExtra attention is needed