Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bump immer and minimist #3724

Merged
merged 2 commits into from
Apr 12, 2022
Merged

chore: bump immer and minimist #3724

merged 2 commits into from
Apr 12, 2022

Conversation

mc-jones
Copy link
Contributor

This PR resolved two critical security issues:

  1. immer - https://github.com/artsy/reaction/security/dependabot/36
  2. minimist - https://github.com/artsy/reaction/security/dependabot/55

Note: minmist was brought in through a transitive dependency on mkdirp which was resolved in mkdirp@0.5.6, resulting in the bump to mkdirp.

@mc-jones mc-jones requested a review from a team April 11, 2022 13:54
@mc-jones mc-jones self-assigned this Apr 11, 2022
@artsy-peril artsy-peril bot added the Version: Minor Indicates that this PR should have a minor deploy, usually for new features label Apr 11, 2022
@mc-jones mc-jones merged commit b1556cd into main Apr 12, 2022
@mc-jones mc-jones deleted the mc-jones/fix-sec-issues branch April 12, 2022 12:57
@artsyit
Copy link
Contributor

artsyit commented Apr 12, 2022

🚀 PR was released in v29.5.0 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
released Version: Minor Indicates that this PR should have a minor deploy, usually for new features
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants