Skip to content
This repository was archived by the owner on Mar 20, 2025. It is now read-only.

fix: luxon-related high risk security (2.4.0→2.5.2)#20

Merged
OlivierAlbertini merged 1 commit intoVilledeMontreal:mainfrom
beltschatsar:feature/fix-luxon-related-high-risk-sec
Oct 27, 2023
Merged

fix: luxon-related high risk security (2.4.0→2.5.2)#20
OlivierAlbertini merged 1 commit intoVilledeMontreal:mainfrom
beltschatsar:feature/fix-luxon-related-high-risk-sec

Conversation

@beltschatsar
Copy link
Copy Markdown
Contributor

@beltschatsar beltschatsar commented Oct 25, 2023

More info: GHSA-3xq5-wjfh-ppjc

This pr do not pollute lock file with registry other than npm

@beltschatsar beltschatsar marked this pull request as draft October 25, 2023 20:22
@beltschatsar beltschatsar marked this pull request as ready for review October 26, 2023 14:16
@beltschatsar beltschatsar force-pushed the feature/fix-luxon-related-high-risk-sec branch from 32003fb to 28f231e Compare October 26, 2023 15:12
Signed-off-by: Daniel Brodeur <daniel.brodeur@montreal.ca>
@beltschatsar beltschatsar force-pushed the feature/fix-luxon-related-high-risk-sec branch from 28f231e to c5e918b Compare October 26, 2023 15:19
@beltschatsar beltschatsar marked this pull request as draft October 26, 2023 15:22
@beltschatsar beltschatsar changed the title ci: fix registry problem in lock file fix: luxon-related high risk security Oct 26, 2023
@beltschatsar beltschatsar changed the title fix: luxon-related high risk security fix: luxon-related high risk security (2.4.0→2.5.2) Oct 26, 2023
@beltschatsar beltschatsar marked this pull request as ready for review October 26, 2023 15:26
@OlivierAlbertini OlivierAlbertini added the dependencies Pull requests that update a dependency file label Oct 27, 2023
@OlivierAlbertini OlivierAlbertini merged commit 1774726 into VilledeMontreal:main Oct 27, 2023
@beltschatsar beltschatsar deleted the feature/fix-luxon-related-high-risk-sec branch October 27, 2023 11:24
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants