This repository has been archived by the owner on Oct 20, 2020. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 20
Do periodic security update (yarn audit) #239
Labels
Comments
This was referenced Sep 11, 2020
Adding: #240 (uglifyjs-webpack-plugin) |
Adding: #241 (eslint-config-liferay) In case you're wondering why it sent us a PR for one of our own dependencies, I guess it sent this PR because the underlying vulnerability in lodash (via eslint-plugin-notice). |
Whoops, wrong button. |
Adding: #242 (jest) |
Adding: #243 (prettier) |
Adding: #244 (fs-extra) |
Adding: #245 ( |
Adding: #246 ( Although will probably move this project into the monorepo before the next audit, at which time it will get the newer shared version of Jest anyway. |
Whatever is left on the audit list is going to be handled in liferay/liferay-frontend-projects#112 so I'm going to close this one. |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Similar to issues in other repos:
This issue will substitute these currently open dependabot PRs:
Note that in this repo, too, we applied new config to limit Dependabot to one open PR at a time — it will still "spam" us, in the sense that if we close that PR it can open another, but at least we won't have up to 10 open PRs in the list at any one time.
More context on our policy here: https://github.com/liferay/liferay-frontend-guidelines/blob/master/general/security.md
The text was updated successfully, but these errors were encountered: