Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): upgrade @storybook to fix markdown-to-jsx vulnerability #568

Merged
merged 1 commit into from
Dec 9, 2024

Conversation

jlandic
Copy link
Contributor

@jlandic jlandic commented Dec 9, 2024

Context

Vanta vulnerability found in the markdown-to-jsx package: https://app.eu.vanta.com/vulnerabilities/findings-by-asset/660bed900682cd872f282c03
CVE record: https://nvd.nist.gov/vuln/detail/cve-2024-21535

Github tried to bump the version of the markdown-to-jsx package, without success, as it's only included as a dependency of @storybook.

What does this PR do?

  • Bump the @storybook version in order to get rid of a vulnerability in markdown-to-jsx

@jlandic jlandic added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Dec 9, 2024
@jlandic jlandic requested a review from mdubus December 9, 2024 11:20
Copy link
Member

@mdubus mdubus left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM ✨🦕 🌻

@mdubus mdubus merged commit a3bb6c6 into main Dec 9, 2024
4 checks passed
@mdubus mdubus deleted the chore-bump-markdown-to-jsx branch December 9, 2024 11:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants