Skip to content

Request: Update hogan.js dependency to maintained fork #565

@jroytman

Description

@jroytman

Hello,

I noticed that diff2html currently depends on hogan.js@3.0.2, which has not been updated in over a decade and pulls in a deprecated version of mkdirp. This results in persistent deprecation warnings for downstream projects, and since we’re publishing our own package that depends on diff2html, these warnings surface for our customers as well.

There are community-maintained forks of hogan.js that address this issue. For example, one recent fork replaces mkdirp with native Node.js calls (https://github.com/disastrous-charly/hogan.js).

Would you be open to switching diff2html to depend on a maintained fork of hogan.js, or accepting a PR that updates this dependency? This would help clean up warnings and improve security hygiene for downstream users. Thanks for your work on this project, and please let me know your thoughts.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions