Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Internal: add resolution for vulnerable ws package #1539

Merged
merged 1 commit into from Jun 7, 2021

Conversation

dangerismycat
Copy link
Contributor

Security alert

ws is used by two dependencies: jsdom and webpack-dev-server. Unfortunately neither have upgraded to address this vulnerability yet, and they are on different major versions (7.x.x and 6.x.x respectively).

This PR adds a resolution for the earliest fixed version (7.4.6). 馃 that webpack-dev-server still works!

@dangerismycat dangerismycat added dependencies Pull requests that update a dependency file patch release Patch release labels Jun 7, 2021
@netlify
Copy link

netlify bot commented Jun 7, 2021

鉁旓笍 Deploy Preview for gestalt ready!

馃敤 Explore the source changes: 113cf44

馃攳 Inspect the deploy log: https://app.netlify.com/sites/gestalt/deploys/60be87ed2672b700089d5253

馃槑 Browse the preview: https://deploy-preview-1539--gestalt.netlify.app/

@dangerismycat dangerismycat marked this pull request as ready for review June 7, 2021 22:03
@dangerismycat dangerismycat requested a review from a team as a code owner June 7, 2021 22:03
@dangerismycat dangerismycat merged commit 5f3144e into pinterest:master Jun 7, 2021
@dangerismycat dangerismycat deleted the update-ws-dependency branch June 7, 2021 22:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file patch release Patch release
Projects
None yet
2 participants