Skip to content
This repository has been archived by the owner on Oct 20, 2020. It is now read-only.

Do periodic security update (yarn audit) #239

Closed
wincent opened this issue Sep 11, 2020 · 9 comments
Closed

Do periodic security update (yarn audit) #239

wincent opened this issue Sep 11, 2020 · 9 comments
Labels

Comments

@wincent
Copy link
Contributor

wincent commented Sep 11, 2020

Similar to issues in other repos:

This issue will substitute these currently open dependabot PRs:

Note that in this repo, too, we applied new config to limit Dependabot to one open PR at a time — it will still "spam" us, in the sense that if we close that PR it can open another, but at least we won't have up to 10 open PRs in the list at any one time.

More context on our policy here: https://github.com/liferay/liferay-frontend-guidelines/blob/master/general/security.md

@wincent
Copy link
Contributor Author

wincent commented Sep 11, 2020

Adding: #240 (uglifyjs-webpack-plugin)

@wincent
Copy link
Contributor Author

wincent commented Sep 14, 2020

Adding: #241 (eslint-config-liferay)

In case you're wondering why it sent us a PR for one of our own dependencies, I guess it sent this PR because the underlying vulnerability in lodash (via eslint-plugin-notice).

@wincent wincent closed this as completed Sep 14, 2020
@wincent
Copy link
Contributor Author

wincent commented Sep 14, 2020

Whoops, wrong button.

@wincent
Copy link
Contributor Author

wincent commented Sep 21, 2020

Adding: #242 (jest)

@wincent wincent removed the wontfix label Sep 28, 2020
@wincent
Copy link
Contributor Author

wincent commented Sep 28, 2020

Adding: #243 (prettier)

@wincent
Copy link
Contributor Author

wincent commented Oct 5, 2020

Adding: #244 (fs-extra)

@wincent
Copy link
Contributor Author

wincent commented Oct 13, 2020

Adding: #245 (publish-please)

@wincent
Copy link
Contributor Author

wincent commented Oct 19, 2020

Adding: #246 (jest)

Although will probably move this project into the monorepo before the next audit, at which time it will get the newer shared version of Jest anyway.

@wincent
Copy link
Contributor Author

wincent commented Oct 19, 2020

Whatever is left on the audit list is going to be handled in liferay/liferay-frontend-projects#112 so I'm going to close this one.

@wincent wincent closed this as completed Oct 19, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

1 participant