Skip to content
This repository has been archived by the owner on Dec 5, 2020. It is now read-only.

Do periodic security update (yarn audit) #504

Closed
wincent opened this issue Sep 7, 2020 · 17 comments
Closed

Do periodic security update (yarn audit) #504

wincent opened this issue Sep 7, 2020 · 17 comments
Labels

Comments

@wincent
Copy link
Contributor

wincent commented Sep 7, 2020

This issue is a reminder to do a periodic security update; analogous to the issue we opened in liferay-npm-tools.

This substitutes these currently open dependabot PRs:

Will also be pushing a PR analogous to this one, which will update our dependabot config.

Please see #199 for some historical context about yarn audit in this repo; I expect we'll keep that open as the "reference" issue containing our overall policy for security-related updates in this repo, and create smaller issues like this one for periodic updates. (This repo has some old legacy dependencies, but is mostly internal/developer facing with little or no production-level/runtime exposure, so the audit output is simultaneously very noisy, but needs to be weighed appropriately given the factors which significantly mitigate risks.)

@wincent
Copy link
Contributor Author

wincent commented Sep 7, 2020

Adding: #506 (sinon)

@wincent
Copy link
Contributor Author

wincent commented Sep 7, 2020

Adding: #507 (minimist, again)

@wincent
Copy link
Contributor Author

wincent commented Sep 14, 2020

@wincent
Copy link
Contributor Author

wincent commented Sep 14, 2020

Adding: #511 (lodash, again)

@wincent
Copy link
Contributor Author

wincent commented Sep 21, 2020

Adding: #512 (opn)

@wincent
Copy link
Contributor Author

wincent commented Sep 28, 2020

Adding: #516 (node-bourbon)

@wincent
Copy link
Contributor Author

wincent commented Oct 5, 2020

Adding: #520 (npm-keyword)

@wincent
Copy link
Contributor Author

wincent commented Oct 13, 2020

Adding: #523 (liferay-frontend-theme-styled)

🤦‍♂️ — no idea what actually changed between these revs (compare link doesn't work) as we don't actually control the release process. Will have to download them and compare to see the difference...

Here is the diff

Can't see any security-related differences (ie. no dependencies change).

@wincent
Copy link
Contributor Author

wincent commented Oct 19, 2020

Adding: #525 (eslint)

Although TBH will probably move this project into the monorepo before doing this next update.

@wincent
Copy link
Contributor Author

wincent commented Oct 26, 2020

Adding: #526 (got)

@wincent
Copy link
Contributor Author

wincent commented Nov 3, 2020

Adding: #527 (gulp-if)

@wincent
Copy link
Contributor Author

wincent commented Nov 9, 2020

Adding: #529 (liferay-npm-build-tools-common)

🤦‍♂️ — I love it when dependabot tells us about our own projects...

@wincent
Copy link
Contributor Author

wincent commented Nov 16, 2020

Adding: #530 (prettier)

@wincent
Copy link
Contributor Author

wincent commented Nov 23, 2020

Adding: #531 (jest)

@wincent
Copy link
Contributor Author

wincent commented Nov 30, 2020

Adding: #532 (resolve)

@wincent
Copy link
Contributor Author

wincent commented Dec 3, 2020

Adding: #537 (bl).

@wincent
Copy link
Contributor Author

wincent commented Dec 4, 2020

Won't be doing this in this repo — we've migrated over here.

@wincent wincent closed this as completed Dec 4, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

1 participant