Conversation
|
|
@dependabot rebase |
c0167cd to
680b28d
Compare
|
@dependabot recreate |
680b28d to
784dce7
Compare
|
@dependabot recreate |
Removes [tar](https://github.com/isaacs/node-tar). It's no longer used after updating ancestor dependency [storybook](https://github.com/storybookjs/storybook/tree/HEAD/code/core). These dependencies need to be updated together. Removes `tar` Updates `storybook` from 7.6.21 to 10.2.17 - [Release notes](https://github.com/storybookjs/storybook/releases) - [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md) - [Commits](https://github.com/storybookjs/storybook/commits/v10.2.17/code/core) --- updated-dependencies: - dependency-name: tar dependency-version: dependency-type: indirect - dependency-name: storybook dependency-version: 10.2.17 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
d12dd66 to
9790dcc
Compare
|
@copilot can you open a PR against this one that will remove all the storybook update stuff and just keep tar at the patched version to resolve the vulnerability alert? |
|
@llastflowers I've opened a new pull request, #3015, to work on those changes. Once the pull request is ready, I'll request review from you. |
* Initial plan * Patch tar vulnerability (6.2.1→7.5.11) without updating storybook Co-authored-by: llastflowers <55068883+llastflowers@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: llastflowers <55068883+llastflowers@users.noreply.github.com>
Removes tar. It's no longer used after updating ancestor dependency storybook. These dependencies need to be updated together.
Removes
tarUpdates
storybookfrom 7.6.21 to 10.2.17Release notes
Sourced from storybook's releases.
... (truncated)
Changelog
Sourced from storybook's changelog.
... (truncated)
Commits
71dcfa9Bump version from "10.2.16" to "10.2.17" [skip ci]8a7f39aBump version from "10.2.15" to "10.2.16" [skip ci]70dfffbCleanup3e03e88Core: Fix allowedHosts and address options in dev-server354507cMerge pull request #34045 from storybookjs/default-allowed-hosts10347fdMerge pull request #33835 from storybookjs/origin-validationd7a9d2eMerge pull request #34032 from braedenfoster/fix/pnpm-preset-resolution1f4697dMerge pull request #33965 from storybookjs/yann/add-vike-metadata9a94a3aMerge pull request #33885 from storybookjs/copilot/fix-configfile-parser-warning7b4ab63Bump version from "10.2.14" to "10.2.15" [skip ci]Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.