Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade follow-redirects version to address vulnerability issue #2955

Merged
merged 1 commit into from
Sep 16, 2024

Conversation

hstonec
Copy link
Contributor

@hstonec hstonec commented Sep 16, 2024

Motivation

follow-redirects is an indirect dependency and gets resolved to version < 1.15.4 which has vulnerability issue, so the PR explicitly sets the version to address that.

Have you read the Contributing Guidelines on pull requests?

Yes

Test Plan

Download nvm / node as needed (tested on node JS 20, Mac OS)

nvm use 20
npm install -g yarn

Then, install the website:

cd website
yarn

Last but not least, start the website on a local server, and browse it:

yarn start

It should work normally.

Related Issues and PRs

N/A

@facebook-github-bot facebook-github-bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Sep 16, 2024
Copy link

@andywag andywag left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@hstonec hstonec merged commit adb4b3b into main Sep 16, 2024
61 checks passed
@hstonec hstonec deleted the bump-follow-redirects-version branch September 16, 2024 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants