GMS-2022-501: Removal of functional code in faker.js
(updated )
Faker.js helps users create large amounts of data for testing and development. The maintainer deliberately removed the functional code from this package. This appears to be a purposeful and successful attempt to make the package unusable.
References
- fakerjs.dev/update.html
- github.com/Marak/colors.js/commit/074a0f8ed0c31c35d13d28632bd8a049ff136fb6
- github.com/Marak/colors.js/issues/285
- github.com/Marak/colors.js/issues/285%23issuecomment-1008212640
- github.com/advisories/GHSA-5w9c-rv96-fr7g
- github.com/advisories/GHSA-gh88-3pxp-6fm8
- nvd.nist.gov/vuln/detail/CVE-2021-23567
- snyk.io/vuln/SNYK-JS-COLORS-2331906
- www.npmjs.com/package/@faker-js/faker
- www.npmjs.com/package/faker
Detect and mitigate GMS-2022-501 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →