Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High Severity Dependabot alerts for @commercetools-frontend/mc-scripts #2953

Open
nick-loyalty opened this issue Feb 2, 2023 · 1 comment
Labels
🤖 Type: Dependencies Dependency updates or something similar

Comments

@nick-loyalty
Copy link

This issue is relevant to Dependabot alerts, we got two High Severity Alerts from Dependabot as it needs two components update
Screen Shot 2023-02-02 at 12 12 08 pm
Screen Shot 2023-02-02 at 12 12 25 pm

These two components are both relevant to @commercetools-frontend/mc-scripts when we do npm ls
Screen Shot 2023-02-02 at 1 04 23 pm
Screen Shot 2023-02-02 at 1 04 59 pm
As we can see in the above, with the latest @commercetools-frontend/mc-scripts, it is still using minimatch@3.0.4 which Dependabot needs minimatch@3.0.5 and json5@0.5.1 which Dependabot needs json5@1.0.2.

Can we upgrade the @commercetools-frontend/mc-scripts to support newer version minimatch and json5 ?

@nick-loyalty nick-loyalty added the 🐛 Type: Bug Something isn't working label Feb 2, 2023
@kark kark added 🤖 Type: Dependencies Dependency updates or something similar and removed 🐛 Type: Bug Something isn't working labels Feb 2, 2023
@kark
Copy link
Contributor

kark commented Feb 2, 2023

Hi @nick-loyalty,

thank you for creating the issue.
We'll look into it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
🤖 Type: Dependencies Dependency updates or something similar
Projects
None yet
Development

No branches or pull requests

2 participants