Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependencies with critical vulnerabilities #248

Merged
merged 5 commits into from
Nov 2, 2023

Conversation

dstaley
Copy link
Contributor

@dstaley dstaley commented Nov 2, 2023

🎟️ Asana Task


Description

This PR updates internal dependencies that have critical vulnerabilities. The majority of these changes only impact developers who are running npm install within the repo; only one of the vulnerable dependencies is actually installed for consumers of the @hashicorp/platform-cli package, which has received a patch bump to reflect the new version of ejs.

PR Checklist 🚀

  • Conduct thorough self-review.
  • Add or update tests as appropriate.
  • Write a useful description (above) to give reviewers appropriate context.
  • Identify (in the description above) and document (add Asana tasks on this board) any technical debt that you're aware of, but are not addressing as part of this PR.

Copy link

changeset-bot bot commented Nov 2, 2023

🦋 Changeset detected

Latest commit: aca995f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@hashicorp/platform-cli Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@dstaley dstaley merged commit 22eea7c into main Nov 2, 2023
3 checks passed
@dstaley dstaley deleted the ds.resolve-alerts branch November 2, 2023 20:24
@hashibot-web hashibot-web mentioned this pull request Jul 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant