Skip to content

[ BB2-2800 ] Snyk critical vuln - babel traverse upgrade to 7.23.2#45

Merged
oragame merged 3 commits intomasterfrom
BB2-2800-snyk-critical-babel-traverse
Nov 7, 2023
Merged

[ BB2-2800 ] Snyk critical vuln - babel traverse upgrade to 7.23.2#45
oragame merged 3 commits intomasterfrom
BB2-2800-snyk-critical-babel-traverse

Conversation

@oragame
Copy link
Copy Markdown
Contributor

@oragame oragame commented Nov 2, 2023

JIRA Ticket:
BB2-2800

User Story or Bug Summary:
Snyk critical finding - Babel/traverse

https://security.snyk.io/vuln/SNYK-JS-BABELTRAVERSE-5962462

Fixed in: @babel/traverse@7.23.2, @8.0.0-alpha.4

What Does This PR Do?

  • This PR upgrades babel/traverse to v7.23.2 to address a critical vulnerability reported by Snyk.
  • Also adds the ./bluebutton-config.json to the gitignore for developer purposes.
  • Upgrade the node version to 16 on the git workflow (was failing with v14)

What Should Reviewers Watch For?

If you're reviewing this PR, please check these things, in particular:

  • Does the app run as expected?

@oragame oragame changed the title Bb2 2800 snyk critical babel traverse [ BB2-2800 ] Snyk critical vuln - babel traverse upgrade to 7.23.2 Nov 2, 2023
@oragame oragame requested review from ajshred and dtisza1 November 3, 2023 17:44
Copy link
Copy Markdown
Contributor

@dtisza1 dtisza1 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good to me!

Copy link
Copy Markdown

@ajshred ajshred left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@oragame oragame merged commit 0b4f534 into master Nov 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants