[Pkg-javascript-devel] Bug#976331: node-compression-webpack-plugin, node-copy-webpack-plugin, node-uglifyjs-webpack-plugin: contains hidden embedded nodejs module serialize-javascript

Jonas Smedegaard dr at jones.dk
Thu Dec 3 11:44:19 GMT 2020


Package: node-compression-webpack-plugin,node-copy-webpack-plugin,node-uglifyjs-webpack-plugin
Severity: important

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

These source packages embed nodejs module serialize-javascript
without offering it as virtual binary package:

 node-compression-webpack-plugin
 node-copy-webpack-plugin
 node-uglifyjs-webpack-plugin

Please embed in only one source package provided as versioned virtual package,
and drop in other source packages instead depending on the virtual package.

Severity raised since the lack of virtual package blocks upgrading node-terser.


 - Jonas

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAl/Iz5AACgkQLHwxRsGg
ASG6Dg//V6dsWFrsdb1fOvjtGMZNv/hpab1B9x9tP4aJdqm42r4VNlnd3m2Di8vQ
OKPUZBMmCgLbsWzEILkNGy33kg+FfCvOWiHTLY+dZHxKIkfn6qXU/crEqoGFI4Id
CQHgGBXgN10teuclHyjCX3kmYLFYc9QdzMRf4dK+v3+EP0LXAMehu3WqMhifewD5
CNdgU327gmtx5Jv6kaeILSFLx+jAZ+hhCetBfQHTTkWhmx2QZmPSjjv8Lb6piy6U
2GZKths9sqBOFTeAhByqO+Tli5qYgcvfrgGVl2avKBwKGEAF+/jXPw8cq1Jqojhx
Hdb2ZFfEQWNZ9LNt8VThyuuOa83wKwLYmx8PFF/rCf5hESKAt6H61uF4KqbIfyhn
EvW7FIhkY7rBIVgFfA+X2ol9JtpJ2vBFyJC3OS23Ymkh8KEv0Pozl/20/Xztizef
l23219Jetv9b+4gDaF1gZZEWZTtpd9NRgDfKpnp21z/8Q+oqQmJtpkaa8fVYTkPo
2NIgSvtN27YAofG3xbfaKJkZ1zhFO0wv5qkDow3E8Tt6QOctkxc6IqC8NOyY8VDX
5IIdRqiUnC2ivw2kGV5NPs1xyGSnuWgrKM5AvSG6FOAN9VVXR62xv2ri+3w+2L+k
xWdf1Rrw1aEnC3iPWVaqopBmIhQ8B1oetd396vECKtyonSGxpTw=
=DRO0
-----END PGP SIGNATURE-----



More information about the Pkg-javascript-devel mailing list