-
-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: Remove shell-quote
resolution
#8820
Conversation
Bitrise✅✅✅ Commit hash: 4c27572 Note
|
eb7beec
to
0bbd390
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
0bbd390
to
d469468
Compare
This resolution was added in #4559 to resolve a security advisory, but it was needed then due to another dependency that was pinned on a vulnerable verison of this package (v1.6.1). We don't have that in our dependency tree anymore, so we aren't asking for the vulnerable version and we no longer need the resolution. Effectively this resolution was just holding this package back, preventing further updates.
d469468
to
ff14603
Compare
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/shell-quote@1.7.3 |
Quality Gate passedIssues Measures |
Description
This resolution was added in #4559 to resolve a security advisory, but it was needed then due to another dependency that was pinned on a vulnerable version of this package (v1.6.1). We don't have that in our dependency tree anymore, so we aren't asking for the vulnerable version and we no longer need the resolution. Effectively this resolution was just holding this package back, preventing further updates.
Related issues
N/A
Manual testing steps
N/A
Screenshots/Recordings
N/A
Pre-merge author checklist
Pre-merge reviewer checklist