Skip to content

Conversation

alexander-smolyakov
Copy link
Contributor

Dev container name:

  • javascript-node;
  • typescript-node.

Description:

This PR addresses the GHSA-c2qf-rxjj-qqgw vulnerability. This vulnerability comes from the semver package, which is used as a dependency in the npm. To address the vulnerability, we need to bump the npm version up to v9.8.1.

Changelog:

  • Dockerfile updated to bump npm version: v9.5.1 -> v9.8.1

Checklist:

  • Checked that applied changes work as expected

@alexander-smolyakov alexander-smolyakov requested a review from a team as a code owner July 26, 2023 13:12
@samruddhikhandale samruddhikhandale merged commit 0f0973a into devcontainers:main Jul 27, 2023
@samruddhikhandale samruddhikhandale mentioned this pull request Jul 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants