Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: pnpm vulnerable deps update #530

Merged
merged 9 commits into from
Apr 22, 2024
Merged

Conversation

emil-litwiniec
Copy link
Contributor

@emil-litwiniec emil-litwiniec commented Apr 19, 2024

Please check if the PR fulfills these requirements

  • The commit message follows our guidelines
  • Tests for the changes have been added (for bug fixes/features)
  • Docs have been added / updated (for bug fixes / features)

What kind of change does this PR introduce?

Update of pnpm packages associated with dependabot alerts. Mostly minor versions and patches, with an exception of docusuarus 2.x.x -> 3.x.x.

Other information:

Handled dependabot alerts:
375, 381, 383, 384, 394, 396, 398, 400, 401, 405, 440

- @babel/traverse dependabot alert #383
- fixes prismjs deep dep vulnerabilities #375, #381
- vulnerable dependency browserify-sign sub dep
- fixes malformed URLs vulnerabilities #405
- fixes dependabot vulnerabilities #396, #398, #400, #401
- fixes dependabot vulnerability #394
- partially fixes dependabot @adobe sub dep vulnerability #440
@emil-litwiniec emil-litwiniec marked this pull request as ready for review April 19, 2024 13:33
@emil-litwiniec emil-litwiniec merged commit 0f5cb7c into master Apr 22, 2024
53 checks passed
@emil-litwiniec emil-litwiniec deleted the chore/pnpm-vul-deps-update branch April 22, 2024 14:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants