Skip to content

Upgrade clap to remove dependency on unmaintained atty crate #84

Closed
@esimkowitz

Description

I have been getting component governance alerts for Grass due to its nested dependency on atty, which has been unmaintained for a few years now and has some compatibility issues with Windows. Your nested dependency on atty comes from clap, though they've moved away from atty as of last year (see clap-rs/clap#4249).

Here's a link to the advisory in the GitHub Security Advisory Database: GHSA-g98v-hv3f-hcfr

Metadata

Assignees

No one assigned

    Labels

    fixed in masterThis issue has been resolved, but the change hasn't been released to crates.io

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions