Skip to content

Update @grpc/grpc-js #427

@denyeart

Description

@denyeart

Security vulnerability scan found an issue with grpc-js:
https://github.com/hyperledger/fabric-chaincode-node/actions/runs/9475979432

I was going to update fabric-shim package.json to 1.8.22, but then realized I don't understand all the dependency files such as common/config/rush/pnpm-lock.yaml. Is this file managed by pnpm or rush? What command should be used to update the dependencies?

Is looks like CONTRIBUTING.md has information about rush, but I wanted to confirm that information is up to date and perhaps update it with the proper rush guidance for updating a dependency.

Also, is it typically safe and advisable to jump to new minor versions of grpc-js, e.g. 1.9.x or 1.10.x?

@bestbeforetoday @mbwhite Can you advise?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions