Skip to content

chore: bump security related js vendor dependencies#1187

Merged
JammingBen merged 1 commit intomasterfrom
bump-dependencies-sec
Aug 8, 2023
Merged

chore: bump security related js vendor dependencies#1187
JammingBen merged 1 commit intomasterfrom
bump-dependencies-sec

Conversation

@fschade
Copy link
Copy Markdown
Contributor

@fschade fschade commented Aug 8, 2023

Description

Bump security related vendor js dependencies, some dependencies still do not have fixed the peer dependency.

Overview

https://github.com/owncloud/activity/security/dependabot

Details

Prototype Pollution in minimist

https://github.com/owncloud/activity/security/dependabot/16, no upstream solution available, bumped via yarn resolutions

json-schema is vulnerable to Prototype Pollution

https://github.com/owncloud/activity/security/dependabot/5, no upstream solution available, bumped via yarn resolutions

json-schema is vulnerable to Prototype Pollution

https://github.com/owncloud/activity/security/dependabot/13, no upstream solution available, bumped via yarn resolutions

@CLAassistant
Copy link
Copy Markdown

CLAassistant commented Aug 8, 2023

CLA assistant check
All committers have signed the CLA.

@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud Bot commented Aug 8, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@JammingBen JammingBen merged commit ad7fb85 into master Aug 8, 2023
@delete-merged-branch delete-merged-branch Bot deleted the bump-dependencies-sec branch August 8, 2023 12:10
@fschade fschade mentioned this pull request Aug 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants