Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SSR-4650: Resolve critical security alert #189

Conversation

huuchi1778
Copy link
Contributor

@huuchi1778 huuchi1778 commented May 23, 2024

Background
This is the resolution for a critical Dependabot alert related to the @babel/traverse package used by @babel/core and its dependencies. As described in the Vulnerability details, upgrading @babel/core to a version >=7.23.2 will automatically pull in a non-vulnerable version of @babel/traverse.

Detail of Action

  • Changed the version of @babel/core used by kintone-cli from 7.22.15 to 7.24.5 (latest)
  • Changed the version of @babel/core in the template file used by apps created by kintone-cli from 7.22.9 to 7.24.5 (latest)

----- Additional Implementation -----
[Reason]
Following the review comment

[Detail of Action]

@trung-doan trung-doan merged commit cbe534b into SSR-4650_Resolve_dev_and_deploy_command_issue May 30, 2024
1 check passed
@trung-doan trung-doan deleted the SSR-4650_Resolve_critical_dependabot_alert branch May 30, 2024 02:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants