pug has not been updated in several months, and its dependency tree includes a vulnerability in an old version of acorn via with which has not been updated in 2 years.
https://www.npmjs.com/advisories/1488
Since a fix would require updating several other packages, we should replace it with an actively‑maintained solution. One possibility is handlebars.
pug has not been updated in several months, and its dependency tree includes a vulnerability in an old version of acorn via with which has not been updated in 2 years.
https://www.npmjs.com/advisories/1488
Since a fix would require updating several other packages, we should replace it with an actively‑maintained solution. One possibility is handlebars.