Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump babel version to resolve lodash vulnerability #1376

Merged
merged 2 commits into from Jul 20, 2020
Merged

Conversation

philmcmahon
Copy link
Contributor

Summary

Apparently there's a vulnerability in the version of lodash that our babel libraries pull in. This appears to have been resolved in recent versions of babel. This PR bumps our babel versions. I've tested in the simulator and babel is only used for building the app so hopefully this is a safe change.

@philmcmahon philmcmahon changed the title Pm bump lodash Bump babel version to resolve lodash vulnerability Jul 20, 2020
Copy link
Contributor

@mohammad-haque mohammad-haque left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

Let's push this to internal beta for through testing.

@philmcmahon philmcmahon merged commit 57dffbe into master Jul 20, 2020
@philmcmahon philmcmahon deleted the pm-bump-lodash branch July 20, 2020 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants