Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): update vulnerable versions #649

Closed
wants to merge 4 commits into from

Conversation

hitesh-parmar
Copy link
Contributor

Solves #648

No new versions will be released as there is no direct dependency on upgraded modules

Fixes
GHSA-c2qf-rxjj-qqgw - Also fixed in SAP/open-ux-tools#1078
GHSA-rc47-6667-2j5j
GHSA-9c47-m6qq-7p4h

GHSA-mxhp-79qh-mcx6 - no fix available

Result of pnpm audit after this PR

image

@changeset-bot
Copy link

changeset-bot bot commented Jun 26, 2023

⚠️ No Changeset found

Latest commit: 8279728

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@hitesh-parmar hitesh-parmar marked this pull request as draft June 26, 2023 17:10
@sonarcloud
Copy link

sonarcloud bot commented Jun 26, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@hitesh-parmar hitesh-parmar marked this pull request as ready for review June 26, 2023 17:32
Copy link
Contributor Author

@hitesh-parmar hitesh-parmar left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

git commit formats pnpm-lock.yaml file, hence it becomes difficult to review the changes

image

@hitesh-parmar
Copy link
Contributor Author

Hi @nlunets, Could you please review this PR?

@nlunets
Copy link
Member

nlunets commented Jun 27, 2023

Thanks @hitesh-parmar for letting me know, i'm superseding this one with.#652 which solvs the issue without relying on fixed versions

@nlunets nlunets closed this Jun 27, 2023
@nlunets nlunets deleted the fix/648/updateVulnerableVersions branch June 27, 2023 04:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants