chore(root): update audit expiries - #4576
Conversation
|
Your PR was set to target |
|
Added fix in last commit, I can rebase if you want to comb through these before a refined and reviewed option. |
There was a problem hiding this comment.
Had a look into some of the new vulnerabilities and I believe it might be possible to fix a few of them by updating the tar and js-yaml override versions in each of the packages' package.jsons
There was a problem hiding this comment.
Want me to add these lockfile changes to this PR?
There was a problem hiding this comment.
Yes that would be great, thanks :)
There was a problem hiding this comment.
If possible, it would be good if the notes for the new vulnerabilities that have been added were more descriptive, e.g. which package is affected - to match the level of detail of the existing vulnerability notes
4697d10 to
3e9a0fc
Compare
|
@GCHQ-Developer-847 PTAL! Did my best to split this work into chunks so you can follow the fix graph. I was unable to upgrade "js-yaml". |
GCHQ-Developer-847
left a comment
There was a problem hiding this comment.
Looks good to me now - thank you for the contribution! :)
Summary of the changes
Updates audits with one month. Notice if you run
npm run auditthere's new ghsa's that hasnt been added in the audit-ci.json, so CI will fail until those are added. Believe this work is best for the core team to tackle.Related issue
N/A
Checklist
General
Testing
Accessibility
Resize/zoom behaviour
System modes
Testing content extremes