Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: replace atty with is-terminal #4249

Merged
merged 1 commit into from
Nov 24, 2022
Merged

Conversation

jcgruenhage
Copy link
Contributor

Not sure whether this would be something you'd want to have, but I'm a bit
unhappy with how widespread the atty crate is being used, because it both has a
soundness issue on Windows and
even though a well reviewed fix for that issue is available it hasn't been
merged, making it look like atty is unmaintained.

Luckily, someone has created a new crate which is re-using a lot of the code
from atty, but with the soundness issue fixed, which has a nice API as you can
tell here. My suggestion would be to switch to this instead.

Cargo.toml Outdated Show resolved Hide resolved
@jcgruenhage
Copy link
Contributor Author

Updated this again to use is-terminal 0.4.0 and rebased on current master.

@epage epage merged commit fb1d960 into clap-rs:master Nov 24, 2022
@jcgruenhage jcgruenhage deleted the replace-atty branch November 24, 2022 16:35
jpgrayson added a commit to stacked-git/stgit that referenced this pull request Nov 28, 2022
This follows suit with clap, which also changed to is-terminal, to
eliminate a redundant dependency and perhaps have a better maintained
library.

Refs: clap-rs/clap#4249
etehtsea added a commit to etehtsea/spin that referenced this pull request Dec 11, 2022
primeos-work added a commit to primeos-work/butido that referenced this pull request Jul 31, 2023
The "atty" crate is unmaintained [0] and also causes a low severity
GitHub advisory (GHSA-g98v-hv3f-hcfr; only affects windows though) [1]:
> A Pull Request with a fix has been provided over a year ago but the
> maintainer seems to be unreachable.
> Last release of atty was almost 3 years ago.

The "clap" crate already switched to "is-terminal" [2] so we can simply
use the latter without having to pull in additional dependencies.
The "is-terminal" crate can also be considered a successor [3]:
> This crate is derived from the atty crate with PR 51 bug fix and PR 54
> port to windows-sys applied.

[0]: softprops/atty#57
[1]: https://github.com/science-computing/butido/security/dependabot/9
[2]: clap-rs/clap#4249
[3]: https://crates.io/crates/is-terminal
primeos-work added a commit to primeos-work/butido that referenced this pull request Jul 31, 2023
The "atty" crate is unmaintained [0] and also causes a low severity
GitHub advisory (GHSA-g98v-hv3f-hcfr; only affects windows though) [1]:
> A Pull Request with a fix has been provided over a year ago but the
> maintainer seems to be unreachable.
> Last release of atty was almost 3 years ago.

The "clap" crate already switched to "is-terminal" [2] so we can simply
use the latter without having to pull in additional dependencies.
The "is-terminal" crate can also be considered a successor [3]:
> This crate is derived from the atty crate with PR 51 bug fix and PR 54
> port to windows-sys applied.

[0]: softprops/atty#57
[1]: https://github.com/science-computing/butido/security/dependabot/9
[2]: clap-rs/clap#4249
[3]: https://crates.io/crates/is-terminal

Signed-off-by: Michael Weiss <[email protected]>
jszwedko added a commit to vectordotdev/vector that referenced this pull request Oct 27, 2023
`atty` seems to be unmaintained and vulnerable to GHSA-g98v-hv3f-hcfr.
I followed `clap`'s lead and replaced with `is-termianl`
(clap-rs/clap#4249).

Signed-off-by: Jesse Szwedko <[email protected]>
github-merge-queue bot pushed a commit to vectordotdev/vector that referenced this pull request Oct 27, 2023
`atty` seems to be unmaintained and vulnerable to GHSA-g98v-hv3f-hcfr.
I followed `clap`'s lead and replaced with `is-termianl`
(clap-rs/clap#4249).

Signed-off-by: Jesse Szwedko <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants