Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Internal] Update dependencies to remove most vulnerabilities #98

Merged
merged 7 commits into from Feb 19, 2021

Conversation

aricallen
Copy link
Contributor

We had 5 critical vulns and this PR should take care of 4 of them plus many other vulns. Unfortunately we still have one that I can't seem to get around without dropping support for electron and/or some major breaking change updates.

The remaining critical dep is constantinople which is still required by some modules Inspect depends on. I tried to update the other deps but that started to break the electron build and would require a larger overhaul.

sysdig-inspect@0.7.3 /Users/aric/Sites/sysdig/sysdig-inspect
└─┬ electron-prebuilt-compile@3.0.13
  └─┬ electron-compilers@5.9.0
    └─┬ jade@1.11.0
      └── constantinople@3.0.2 

@aricallen aricallen self-assigned this Feb 19, 2021
@sonarcloud
Copy link

sonarcloud bot commented Feb 19, 2021

Kudos, SonarCloud Quality Gate passed!

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@aricallen aricallen merged commit a71c0fd into dev Feb 19, 2021
@aricallen aricallen deleted the deps-take2 branch February 19, 2021 00:27
therealbobo pushed a commit to therealbobo/sysdig-inspect that referenced this pull request Jul 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant