Skip to content

Update vulnerable dependencies (ajv, minimatch, diff and serialize-javascript)#566

Open
willgibson-madetech wants to merge 1 commit intotcort:masterfrom
willgibson-madetech:update-vulnerable-dependencies
Open

Update vulnerable dependencies (ajv, minimatch, diff and serialize-javascript)#566
willgibson-madetech wants to merge 1 commit intotcort:masterfrom
willgibson-madetech:update-vulnerable-dependencies

Conversation

@willgibson-madetech
Copy link
Copy Markdown

Used npm audit fix to fix ajv and minimatch.

Added overrides in package.json to force diff to ^8.0.3 and serialize-javascript to
^7.0.4, since mocha's latest release still bundles the vulnerable versions. We should be able to remove these overrides when mocha catches up.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant