Skip to content

Dependencies: Update dependency packages using npm audit fix#860

Merged
amotl merged 1 commit intomainfrom
npm-audit-202410
Oct 25, 2024
Merged

Dependencies: Update dependency packages using npm audit fix#860
amotl merged 1 commit intomainfrom
npm-audit-202410

Conversation

@amotl
Copy link
Member

@amotl amotl commented Oct 25, 2024

About

Just usual irregular maintenance. What the title says.

Details

List of affected packages: body-parser, cookie, http-proxy-middleware, ip, path-to-regexp, send, tar, webpack.
Intends to mitigate a few warning items on any security scanners (GitHub, OCI image, you name it) that might be used on software artefacts today down the line.

Thoughts

Might also overlap with some Dependabot PRs, so merging this PR may resolve a few of them already.

List of affected packages: body-parser, cookie, http-proxy-middleware,
ip, path-to-regexp, send, tar, webpack.
@cla-bot cla-bot bot added the cla-signed label Oct 25, 2024
@amotl

This comment was marked as off-topic.

@amotl amotl requested review from kneth and surister October 25, 2024 12:05
@amotl amotl marked this pull request as ready for review October 25, 2024 12:05
Copy link
Member

@kneth kneth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewing changes to package-lock.json is always difficult. I assume that there were no changes to package.json.

@amotl amotl merged commit 63720c6 into main Oct 25, 2024
@amotl amotl deleted the npm-audit-202410 branch October 25, 2024 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants