Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: security vulnerabilities in NPM deps #1860

Merged
merged 5 commits into from
May 28, 2024
Merged

Conversation

shumkov
Copy link
Member

@shumkov shumkov commented May 26, 2024

Issue being fixed or feature implemented

❯ yarn npm audit --environment production --all --recursive
├─ glob
│  ├─ ID: glob (deprecation)
│  ├─ Issue: Glob versions prior to v9 are no longer supported
│  ├─ Severity: moderate
│  ├─ Vulnerable Versions: 8.1.0
│  │ 
│  ├─ Tree Versions
│  │  └─ 8.1.0
│  │ 
│  └─ Dependents
│     └─ help-me@npm:4.2.0
│
├─ inflight
│  ├─ ID: inflight (deprecation)
│  ├─ Issue: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
│  ├─ Severity: moderate
│  ├─ Vulnerable Versions: 1.0.6
│  │ 
│  ├─ Tree Versions
│  │  └─ 1.0.6
│  │ 
│  └─ Dependents
│     └─ glob@npm:7.2.0
│
└─ rimraf
   ├─ ID: rimraf (deprecation)
   ├─ Issue: Rimraf versions prior to v4 are no longer supported
   ├─ Severity: moderate
   ├─ Vulnerable Versions: 2.7.1
   │ 
   ├─ Tree Versions
   │  └─ 2.7.1
   │ 
   └─ Dependents
      └─ slocket@npm:1.0.5

What was done?

  • Set resolution for glob and rimraf to versions ^10.3.4 and ^4.4.1 respectively

How Has This Been Tested?

None

Breaking Changes

None

Checklist:

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated relevant unit/integration/functional/e2e tests
  • I have added "!" to the title and described breaking changes in the corresponding section if my code contains any
  • I have made corresponding changes to the documentation if needed

For repository code-owners and collaborators only

  • I have assigned this pull request to a milestone

@shumkov shumkov added this to the v1.0.0 milestone May 26, 2024
@shumkov shumkov requested a review from QuantumExplorer as a code owner May 26, 2024 16:12
@shumkov shumkov force-pushed the fix/security-vulnerabities branch from be9e8f5 to db41c89 Compare May 26, 2024 16:14
@shumkov
Copy link
Member Author

shumkov commented May 28, 2024

I'm going to merge this one to unblock other PRs. @QuantumExplorer is busy and his review is unnecessary since it's a JS work. Reviewed by @pshenmic though.

@shumkov shumkov merged commit 4224881 into v1.0-dev May 28, 2024
17 checks passed
@shumkov shumkov deleted the fix/security-vulnerabities branch May 28, 2024 07:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants