Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WIP - Fixing Gluegun and other dep upgrades #235

Closed
wants to merge 1 commit into from

Conversation

jamonholmgren
Copy link
Member

@GantMan I started working through this but ran out of time. Can you carry the ball forward from here? I've made some progress, but am still getting test failures.

@avaGitHubBot
Copy link

Warnings
⚠️

Changes were made to package.json, but not to package-lock.json - Perhaps you need to run npm install?

Generated by 🚫 dangerJS

@GantMan
Copy link
Member

GantMan commented Dec 30, 2018

Let's hold on this. I have a major PR in progress. It breaks tons of tests an would significantly affect this work. Sorry :( I wish it were done, but it's a pain so I'm taking it slower.

@jamonholmgren
Copy link
Member Author

Can you bring Gluegun up to latest while you're at it, @GantMan ? I'd love to be able to use Solidarity to test new Gluegun releases.

@GantMan
Copy link
Member

GantMan commented Jan 3, 2019

@jamonholmgren if you merge or approve and I merge #236 then you can jump back into this one.

@petekp petekp mentioned this pull request Feb 12, 2020
@derekgates
Copy link

Any updates on merging this PR or #249 ?

I look forward to using this system at work but the audit problems prevent this.

  Low             Prototype Pollution
  Package         lodash
  Patched in      >=4.17.5
  Dependency of   solidarity
  Path            solidarity > gluegun > cli-table2 > lodash
  More info       https://npmjs.com/advisories/577


  High            Prototype Pollution
  Package         lodash
  Patched in      >=4.17.11
  Dependency of   solidarity
  Path            solidarity > gluegun > cli-table2 > lodash
  More info       https://npmjs.com/advisories/782

  High            Prototype Pollution
  Package         lodash
  Patched in      >=4.17.12
  Dependency of   solidarity
  Path            solidarity > gluegun > cli-table2 > lodash
  More info       https://npmjs.com/advisories/1065

  Moderate        Denial of Service
  Package         axios
  Patched in      >=0.18.1
  Dependency of   solidarity
  Path            solidarity > gluegun > apisauce > axios
  More info       https://npmjs.com/advisories/880

  High            Prototype Pollution
  Package         set-value
  Patched in      >=2.0.1 <3.0.0 || >=3.0.1
  Dependency of   solidarity
  Path            solidarity > gluegun > enquirer > prompt-question >
                  prompt-choices > set-value
  More info       https://npmjs.com/advisories/1012

  High            Prototype Pollution
  Package         set-value
  Patched in      >=2.0.1 <3.0.0 || >=3.0.1
  Dependency of   solidarity
  Path            solidarity > gluegun > enquirer > set-value
  More info       https://npmjs.com/advisories/1012


  High            Prototype Pollution
  Package         set-value
  Patched in      >=2.0.1 <3.0.0 || >=3.0.1
  Dependency of   solidarity
  Path            solidarity > gluegun > prompt-autocompletion > prompt-base >
                  prompt-question > prompt-choices > set-value
  More info       https://npmjs.com/advisories/1012

  High            Prototype Pollution
  Package         set-value
  Patched in      >=2.0.1 <3.0.0 || >=3.0.1
  Dependency of   solidarity
  Path            solidarity > gluegun > prompt-autocompletion >
                  prompt-choices > set-value
  More info       https://npmjs.com/advisories/1012

If this PR is still desired, would it be helpful to resolve the conflicts and rebase/merge this again? I can certainly help with that!

@GantMan GantMan closed this May 5, 2020
@GantMan GantMan deleted the update/gluegun-dep branch May 5, 2020 19:11
@jamonholmgren
Copy link
Member Author

Closing the loop, we are up to Gluegun 4.2.0 (latest as of now is 4.3.1).

"gluegun": "4.2.0",

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants