Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade deps with vulnerabilities #19128

Merged
merged 1 commit into from
Nov 30, 2021
Merged

upgrade deps with vulnerabilities #19128

merged 1 commit into from
Nov 30, 2021

Conversation

alxnddr
Copy link
Member

@alxnddr alxnddr commented Nov 29, 2021

We've got a couple of deps with critical vulnerabilities. Fortunately, these dependencies come from building tools and documentation, which does not threaten the application itself. However, I added resolutions to secure packages for now. Once this PR facebook/create-react-app#11624 gets merged we will be able to remove these package resolutions.

@alxnddr alxnddr marked this pull request as ready for review November 29, 2021 22:56
@alxnddr alxnddr requested a review from a team November 29, 2021 22:56
@alxnddr alxnddr self-assigned this Nov 29, 2021
@codecov
Copy link

codecov bot commented Nov 29, 2021

Codecov Report

Merging #19128 (8fdc4f0) into master (8ea40b6) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master   #19128   +/-   ##
=======================================
  Coverage   64.90%   64.90%           
=======================================
  Files        1866     1866           
  Lines       70677    70677           
  Branches     7762     7762           
=======================================
  Hits        45872    45872           
  Misses      21384    21384           
  Partials     3421     3421           
Flag Coverage Δ
front-end 43.54% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.


Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 8ea40b6...8fdc4f0. Read the comment docs.

@ariya
Copy link
Contributor

ariya commented Nov 29, 2021

Can you rebase to the latest master? That shall fix the CI timeout issue on some of the checks.

@alxnddr alxnddr merged commit c2dfd8d into master Nov 30, 2021
@alxnddr alxnddr deleted the upgrade-deps branch November 30, 2021 13:27
@alxnddr alxnddr mentioned this pull request Nov 30, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants