Skip to content

Remove deprecated prettyoutput package#2

Closed
j0k3r wants to merge 1 commit into
oss-serverless:mainfrom
j0k3r:fix/remove-prettyoutput
Closed

Remove deprecated prettyoutput package#2
j0k3r wants to merge 1 commit into
oss-serverless:mainfrom
j0k3r:fix/remove-prettyoutput

Conversation

@j0k3r
Copy link
Copy Markdown

@j0k3r j0k3r commented Apr 21, 2026

The main reason is that it integrates an old version of lodash (which is hardly locked to 4.17.x). There is two vulns on lodash which are fixed in 4.18.0:

And use an internal solution instead.
Also add test to ensure the result is the same (before/after).

@osls/compose gained attention recently as it has been integrated into serverless-operations/serverless-step-functions#745

image

And use an internal solution instead.
Also add test to ensure the result is the same (before/after).
@GrahamCampbell
Copy link
Copy Markdown
Contributor

Thanks for raising this. I'll fix this in a much larger PR to address the most urgent OSS supply chain issues.

@j0k3r j0k3r deleted the fix/remove-prettyoutput branch April 22, 2026 04:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants