Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update nyc to 13.3.0 to resolve handlebars dependency security concern. #812

Merged
merged 1 commit into from Feb 14, 2019

Conversation

Jkovarik
Copy link
Member

@Jkovarik Jkovarik commented Feb 14, 2019

Updated all nyc dependencies to 13.3.0 to address security audit concerns.

See: https://npmjs.com/advisories/755,
istanbuljs/nyc#991

for more information.

@Jkovarik Jkovarik changed the title Update nyc to 13.3.0 to resolve handlebars dep security concern. Update nyc to 13.3.0 to resolve handlebars dependency security concern. Feb 14, 2019
Copy link
Contributor

@markdboyd markdboyd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These changes look good to me.

Are we really not committing lockfiles for any of our packages? We definitely need to start doing that. Probably as part of the effort when we commit fully to npm or yarn (hopefully the former)

@Jkovarik
Copy link
Member Author

These changes look good to me.

Are we really not committing lockfiles for any of our packages? We definitely need to start doing that. Probably as part of the effort when we commit fully to npm or yarn (hopefully the former)

Agreed, and that probably should hasten our decision to do so.

@Jkovarik Jkovarik merged commit 2ad6b3a into master Feb 14, 2019
@Jkovarik Jkovarik deleted the CUMULUS-1167 branch February 14, 2019 19:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants