8000 security: update JS dependencies which have notified vulnerabilities by bboreham · Pull Request #3763 · weaveworks/scope · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

security: update JS dependencies which have notified vulnerabilities #3763

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 7 commits into from
Mar 20, 2020

Conversation

bboreham
Copy link
Collaborator

I updated five listed on https://github.com/weaveworks/scope/network/alerts:
minimist, acorn, set-value, mixin-deep, sshpk

I did not update clean-css because I believe it's only used at build time.

All changes are point versions only.

I ran yarn-deduplicate as in #3733 prior to starting, and after each change.

@bboreham bboreham mentioned this pull request Mar 19, 2020
@bboreham bboreham merged commit 49db8f6 into master Mar 20, 2020
@bboreham bboreham deleted the yarn-update branch March 20, 2020 12:22
@fbarl
Copy link
Contributor
fbarl commented Mar 20, 2020

I think this is a good way to go @bboreham!

However, once you updated yarn.lock, you could have removed all these entries you added to package.json and reran yarn install - I just did that locally and yarn.lock stayed the same.

That means we maintain the JS security updates from this PR while still keeping package.json relatively clean; let me try making a small follow-up PR for this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants
0