-
Notifications
You must be signed in to change notification settings - Fork 3.5k
[No QA] chore: apply npm audit fix to resolve high security vulns #54286
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[No QA] chore: apply npm audit fix to resolve high security vulns #54286
Conversation
|
Testing this on web now. edit: tested and can confirm that the app builds & runs just fine. |
|
@ Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button] |
mountiny
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thank you!
Reviewer Checklist
Screenshots/VideosAndroid: NativeAndroid: mWeb ChromeiOS: NativeiOS: mWeb SafariMacOS: Chrome / SafariMacOS: Desktop |
6ed9624 to
154a485
Compare
|
Ran the same checks, builds & runs OK. |
|
✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release. |
|
🚀 Deployed to staging by https://github.com/mountiny in version: 9.0.78-0 🚀
|
|
🚀 Deployed to staging by https://github.com/mountiny in version: 9.0.78-0 🚀
|
2 similar comments
|
🚀 Deployed to staging by https://github.com/mountiny in version: 9.0.78-0 🚀
|
|
🚀 Deployed to staging by https://github.com/mountiny in version: 9.0.78-0 🚀
|
|
🚀 Deployed to staging by https://github.com/mountiny in version: 9.0.78-0 🚀
|
1 similar comment
|
🚀 Deployed to staging by https://github.com/mountiny in version: 9.0.78-0 🚀
|
|
🚀 Deployed to staging by https://github.com/mountiny in version: 9.0.78-0 🚀
|
|
🚀 Deployed to production by https://github.com/jasperhuangg in version: 9.0.78-6 🚀
|
@mountiny
Explanation of Change
This PR applies
npm audit fix(without the--forceflag for only nonbreaking changes) to resolve 1 moderate and 2 high security vulnerabilities in the project's npm dependencies. We don't have this as a chore so I applied the fix ad hoc.Before
16 vulnerabilities (4 low, 8 moderate, 4 high)
After
13 vulnerabilities (4 low, 7 moderate, 2 high)
Fixed Issues
$ N/A
PROPOSAL: N/A
Tests
Offline tests
QA Steps
// TODO: These must be filled out, or the issue title must include "[No QA]."
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectiontoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Android: Native
Android: mWeb Chrome
iOS: Native
iOS: mWeb Safari
MacOS: Chrome / Safari
MacOS: Desktop