Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

UI: resolves braces < 3.0.3 dep vulnerability #27642

Closed

Conversation

hellobontempo
Copy link
Contributor

@hellobontempo hellobontempo commented Jun 28, 2024

Description

This PR makes a few dependency package updates to address the security vulnerability in braces v3.0.3. I recommend reviewing by commit, general breakdown of each commit:

  1. Deleted the yarn.lock file and re-ran yarn resolved some of the issues
  2. Added braces to the resolution block resolved some more vulnerable versions

@hellobontempo hellobontempo added this to the 1.18.0-rc milestone Jun 28, 2024
@hellobontempo hellobontempo requested a review from a team as a code owner June 28, 2024 22:45
@github-actions github-actions bot added the hashicorp-contributed-pr If the PR is HashiCorp (i.e. not-community) contributed label Jun 28, 2024
Copy link

Build Results:
All builds succeeded! ✅

Copy link

CI Results: failed ❌

@hellobontempo hellobontempo force-pushed the ui/update-ui-deps-resolve-braces-vulnerability branch from 361e245 to 072ebce Compare July 1, 2024 17:01
@hellobontempo
Copy link
Contributor Author

Unrelated test failures, closing in favor of #27657

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport/1.17.x hashicorp-contributed-pr If the PR is HashiCorp (i.e. not-community) contributed pr/no-changelog ui
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant