Skip to content

Dependency on sass-convert (unmaintained + vulnerabilities)Β #577

@bulutfatih

Description

@bulutfatih

Hi SassDoc maintainers πŸ‘‹

While integrating SassDoc into a modern build pipeline I noticed that the package still depends on sass-convert.

Unfortunately sass-convert (Ruby-based) has been unmaintained for β‰ˆ10 years and flagged with multiple vulnerabilities.

Because SassDoc ships sass-convert as a production dependency, every downstream consumer inherits these risks. Most security scanners now fail our builds by default.

Would it be possible to replace it with a maintained one alternative?

Thanks a lot πŸ™

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions