As part of Security testing, the team reported vulnerability packages in the package-lock.json. We will not use those in runtime in production environments can we remove package.json and package-lock.json from the stable release to avoid this?
Also, I am attaching a patch for the same please review.

CommentFileSizeAuthor
bootstrap_styles_vulnerability.patch388.15 KBsreeram_v

Comments

sreeram_v created an issue. See original summary.

rajab natshah’s picture

Title: Request to remove build dependencies in stable releases » Remove or update build dependencies in stable releases
Component: Miscellaneous » Code
Priority: Major » Normal
Status: Active » Needs work

Thanks, Sreeram, for reporting and patching!

While you are making the above changes, we recommend that you convert this patch to a merge request. Merge requests are preferred over patches. Be sure to hide the old patch files as well.