Needs work
Project:
Bootstrap Styles
Version:
1.1.5
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
20 Mar 2024 at 06:36 UTC
Updated:
21 Mar 2024 at 08:58 UTC
Jump to comment: Most recent
As part of Security testing, the team reported vulnerability packages in the package-lock.json. We will not use those in runtime in production environments can we remove package.json and package-lock.json from the stable release to avoid this?
Also, I am attaching a patch for the same please review.
| Comment | File | Size | Author |
|---|---|---|---|
| bootstrap_styles_vulnerability.patch | 388.15 KB | sreeram_v |
Comments
Comment #2
rajab natshahThanks, Sreeram, for reporting and patching!
While you are making the above changes, we recommend that you convert this patch to a merge request. Merge requests are preferred over patches. Be sure to hide the old patch files as well.