Skip to content

Conversation

@curquiza
Copy link
Member

And update dependencies in playgrounds/html/yarn.lock

@curquiza curquiza added dependencies Improvements or additions to documentation skip-changelog The PR will not appear in the release changelogs labels Jan 27, 2021
@curquiza curquiza requested a review from bidoubiwa January 27, 2021 11:13
@bidoubiwa
Copy link
Contributor

An issue was opened in the parcel repo

You do realize that this isn't an actual issue right? You have to use nodeforge.util.setPath in order to trigger the vulnerability, which parcel does not. These npm warnings just create work for maintainers in most cases due to people complaining in issues like this one.

So we might want to merge just to remove the vulnerability in github interface.

@curquiza
Copy link
Member Author

curquiza commented Feb 3, 2021

bors merge

@bors
Copy link
Contributor

bors bot commented Feb 3, 2021

Build succeeded:

@bors bors bot merged commit c3689c1 into master Feb 3, 2021
@bors bors bot deleted the fix-node-forge-vulnerability branch February 3, 2021 12:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Improvements or additions to documentation skip-changelog The PR will not appear in the release changelogs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants