Thanks to visit codestin.com
Credit goes to github.com

Skip to content

chore: bump versions to remediate critical and high Dependabot vulns #583

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged

Conversation

falconandy
Copy link
Contributor

Summary

Bump versions to remediate critical and high Dependabot vulns

Before: 17 dependabot alers
After: 6 alerts = 3 high + 2 moderate + 1 low

The 3 high-level alerts can't be resolved now: packages karma-sauce-launcher, @docusaurus/core and @docusaurus/preset-classic should be updated by their authors.

Unsupported packages are replaced: watch -> chokidar-cli, rollup-plugin-uglify -> @rollup/plugin-terser

Checklist

  • Does your PR title have the correct title format?
  • Does your PR have a breaking change?: no

@falconandy falconandy force-pushed the AMP-70965-remediate-critical-and-high-dependabot-vulns branch from 8812f1f to 0e95dcb Compare March 20, 2023 08:42
@justin-fiedler justin-fiedler merged commit d7e7cf2 into main Mar 20, 2023
@justin-fiedler justin-fiedler deleted the AMP-70965-remediate-critical-and-high-dependabot-vulns branch March 20, 2023 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants