Closed (fixed)
Project:
once.js
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
2 Mar 2021 at 10:50 UTC
Updated:
17 Mar 2021 at 19:14 UTC
Jump to comment: Most recent
update pacakge dependencies
solves security advisory https://www.npmjs.com/advisories/1623
Package Current Wanted Latest Location Depended by
@esm-bundle/chai 4.1.5 4.3.0 4.3.0 node_modules/@esm-bundle/chai once
@web/test-runner 0.9.13 0.9.13 0.12.15 node_modules/@web/test-runner once
eslint 7.18.0 7.21.0 7.21.0 node_modules/eslint once
rollup 2.38.1 2.40.0 2.40.0 node_modules/rollup once
Start within a Git clone of the project using the version control instructions.
Or, if you do not have SSH keys set up on git.drupalcode.org:
Comments
Comment #3
nod_Comment #4
justafish+1
Comment #6
nod_Comment #7
justafishI'm still seeing vulnerabilities reported at https://git.drupalcode.org/project/once/-/security/vulnerability_report
Comment #8
nod_umm we don't seem to need @esm-bundle/chai, so that's one down
Comment #10
nod_seems to do the trick https://git.drupalcode.org/project/once/-/pipelines/127/security
Comment #12
nod_alerts still things showing up on the report https://git.drupalcode.org/project/once/-/security/vulnerability_report but everything is up to date (on our side) might need to contribute upstream but I don't think we can do much more from here.
Comment #13
justafishThe report is clear now