Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade vulnerable packages #1658

Merged
merged 1 commit into from Aug 24, 2020

Conversation

josescasanova
Copy link
Contributor

@josescasanova josescasanova commented Aug 11, 2020

There are a few dependencies that are running an outdated version of serialize-javascript, which has a remove code execution vulnerability (https://npmjs.com/advisories/1548). This PR updates them. I audited the change logs of the packages and seems like this project doesn't have any breaking changes.

Tests pass and was able to QA locally:
image

@mikkilevon

This comment has been minimized.

@sapegin sapegin merged commit 53bc4bb into styleguidist:master Aug 24, 2020
@sapegin
Copy link
Member

sapegin commented Aug 24, 2020

Thanks!

@styleguidist-bot
Copy link
Collaborator

🎉 This PR is included in version 11.0.9 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants