Skip to content

Commit

Permalink
add example
Browse files Browse the repository at this point in the history
Signed-off-by: himsgupta1122 <hmsgupt@gmail.com>
  • Loading branch information
himsgupta1122 committed Oct 31, 2022
1 parent a171c8f commit 8888817
Showing 1 changed file with 13 additions and 1 deletion.
14 changes: 13 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,4 +7,16 @@

- For nested dependency/sub-deps - In order to enforce package above Vx.y.z, we can add version in the resolutions [section](https://classic.yarnpkg.com/lang/en/docs/selective-version-resolutions/) for all the package sub-deps or specific package sub-dep. For more on version updates please see
[Why](https://classic.yarnpkg.com/lang/en/docs/selective-version-resolutions/#toc-why-would-you-want-to-do-this) and [How](https://classic.yarnpkg.com/lang/en/docs/selective-version-resolutions/#toc-how-to-use-it) to upgrade.

```
Example: foobar@1.x vulnerable package and 1.y is the fix
step 1:
For direct dependency checks:
run: yarn upgrade foobar@1.y
Step 2.
Check for sub deps foobar in other package.
If foobar@1.x exists for subdeps in yarn.lock file
Then edit the package.json file and add **/foobar@1.y in resolution section as shown below to enforce the 1.y.
'resolutions': { "**/foobar": "^1.y",
"**/foo": "^2.x" ,
"**/bar": "^3.k"}

0 comments on commit 8888817

Please sign in to comment.