Skip to content
This repository has been archived by the owner on Aug 13, 2023. It is now read-only.

bump dependencies to latest #1592

Merged
merged 10 commits into from
Aug 6, 2019
Merged

bump dependencies to latest #1592

merged 10 commits into from
Aug 6, 2019

Conversation

thekp
Copy link
Contributor

@thekp thekp commented Aug 5, 2019

Resolves: n/a

Overall change: bumping dependencies in the package.json

Test notes: all these tests are dev dependencies, if they pass on CI the changes should be fine.

I have bumped the following dependencies:


  • I have assigned myself to this PR and the corresponding issues
  • Tests added for new features
  • Test engineer approval

@thekp thekp added simorgh-core-stream dependencies Pull requests that update a dependency file labels Aug 5, 2019
@thekp thekp self-assigned this Aug 5, 2019
@thekp
Copy link
Contributor Author

thekp commented Aug 5, 2019

2 vulnerabilities arise from these dependency bumps

image

@sareh
Copy link
Contributor

sareh commented Aug 5, 2019

Approved pending a separate fix for the vulnerabilities that were introduced here.

@sareh
Copy link
Contributor

sareh commented Aug 5, 2019

Have opened up a PR to fix the vulnerability in storybook-readme: tuchk4/storybook-readme#205 (Noting that pinning to a version without the vulnerability means going from v5.0.6->v3.3.0, so a quick fix forwards would be better in this scenario.)

@PriyaKR
Copy link
Contributor

PriyaKR commented Aug 6, 2019

The changes are dev changes by minor bumps doesn't require a testing effort by a tester as long as the tests on CI pass.

@thekp thekp merged commit 0160871 into latest Aug 6, 2019
@thekp thekp deleted the dependency-bumps branch August 6, 2019 14:52
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file simorgh-core-stream
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants