Skip to content

Upgrade for security advisories#4231

Merged
julienw merged 3 commits intofirefox-devtools:mainfrom
julienw:upgrade-for-security-advisories
Sep 19, 2022
Merged

Upgrade for security advisories#4231
julienw merged 3 commits intofirefox-devtools:mainfrom
julienw:upgrade-for-security-advisories

Conversation

@julienw
Copy link
Contributor

@julienw julienw commented Sep 15, 2022

This upgrades a few of our transitive dependencies.
Then we still have 2 advisories: one for flow-coverage-report, and one coming from alex. Both are not directly tied to the product code so I'm not concerned, even if it would be good to upgrade them eventually too.

@julienw julienw requested a review from canova September 15, 2022 08:50
@@ -9634,13 +9639,12 @@ postcss-value-parser@^4.1.0, postcss-value-parser@^4.2.0:
integrity sha512-1NNCs6uurfkVbeXG4S8JFT9t19m45ICnif8zWLd5oPSZ50QnwMfK+H3jv408d4jw/7Bttv5axS5IiHoLaVNHeQ==

postcss@^7.0.17:
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The v7 version comes from stylelint-config-idiomatic-order. Maybe we should import this package to our tree directly and depend in stylelint-order instead, so that we can upgrade more easily that one?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, it should be possible to do so.

integrity sha1-DY6UaWej2BQ/k+JOKYUl/BsiNfk=
integrity sha512-sGwIGMjhYdW26/IhwK2gkWWI8DRCVO6uj3hYgHT+zD+QL1pa37tM3ujhyfcJIYSbsxp7Gxhy7zrRW/1AHm4BmA==

ansi-regex@^4.1.0:
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ansi regex v4 comes from both flow-coverage-report and alex.

@@ -11658,9 +11655,9 @@ thenify-all@^1.0.0:
thenify ">= 3.1.0 < 4"

"thenify@>= 3.1.0 < 4":
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thenify transitively comes from local-web-server

version "0.2.1"
resolved "https://registry.yarnpkg.com/ansi-regex/-/ansi-regex-0.2.1.tgz#0d8e946967a3d8143f93e24e298525fc1b2235f9"
integrity sha1-DY6UaWej2BQ/k+JOKYUl/BsiNfk=
integrity sha512-sGwIGMjhYdW26/IhwK2gkWWI8DRCVO6uj3hYgHT+zD+QL1pa37tM3ujhyfcJIYSbsxp7Gxhy7zrRW/1AHm4BmA==
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change comes from the fact I deleted all ansi-regex entries before running yarn, and so this regeneated this sha differently after install.

@codecov
Copy link

codecov bot commented Sep 15, 2022

Codecov Report

Base: 88.51% // Head: 88.51% // No change to project coverage 👍

Coverage data is based on head (7002c0f) compared to base (a9ff160).
Patch has no changes to coverable lines.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4231   +/-   ##
=======================================
  Coverage   88.51%   88.51%           
=======================================
  Files         282      282           
  Lines       24758    24758           
  Branches     6613     6613           
=======================================
  Hits        21914    21914           
  Misses       2642     2642           
  Partials      202      202           

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

☔ View full report at Codecov.
📢 Do you have feedback about the report comment? Let us know in this issue.

Copy link
Member

@canova canova left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!
It looks like they are indeed not serious but good to resolve them. Thanks!

@@ -9634,13 +9639,12 @@ postcss-value-parser@^4.1.0, postcss-value-parser@^4.2.0:
integrity sha512-1NNCs6uurfkVbeXG4S8JFT9t19m45ICnif8zWLd5oPSZ50QnwMfK+H3jv408d4jw/7Bttv5axS5IiHoLaVNHeQ==

postcss@^7.0.17:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, it should be possible to do so.

@julienw
Copy link
Contributor Author

julienw commented Sep 19, 2022

thanks!

@julienw julienw merged commit e58d335 into firefox-devtools:main Sep 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants