Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Bump node-sass to address LibSass vulnerabilities
There are a few known security vulnerabilities related to the version of node-sass used in the repo. Both node-sass and LibSass are deprecated, but replacing node-sass with dart-sass fails because EUI does not follow the standard Sass spec. This results in a SassError: `Top-level selectors may not contain the parent selector "&"`. Resolving this problem will have to be done in the long-term, but for now there are branches of node-sass that exist with a newer version of LibSass that does not contain any known security vulnerabilities. Unfortunately, these changes don't exist in any of the main releases, so we must use a specific branch (v5). Details are on the main Sass website: https://sass-lang.com/blog/libsass-is-deprecated Signed-off-by: Tommy Markley <[email protected]>
- Loading branch information