Skip to content

validate-commit-msg@2.14.0 security issues #1626

@tomasmax

Description

@tomasmax

Package

validate-commit-msg@2.14.0 has some security issues, it's deprecated and it's being used in some projects.

Description

This dependabot security warning from the semver-regex dependency is related to the validate-commit-msg package, but it's already deprecated.

It's used with the types from sui-mono.

What alternative could we use? Look into additional information

Expected behavior: To use a maintained library without security issues

Actual behavior:

Additional Information

I did some research and https://github.com/conventional-changelog/commitlint looks a good cadidate to do this job.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions