Skip to content

Update (dev) dependencies flagged by npm-audit#2192

Merged
rgrunber merged 3 commits intoredhat-developer:masterfrom
rgrunber:audit-fix-update
Nov 1, 2021
Merged

Update (dev) dependencies flagged by npm-audit#2192
rgrunber merged 3 commits intoredhat-developer:masterfrom
rgrunber:audit-fix-update

Conversation

@rgrunber
Copy link
Copy Markdown
Member

  • mocha from 8.1.1 to 9.1.3
  • ts-loader from 5.3.1 to 9.2.6
  • Update compatible dependencies of gulp 4.0.2

Signed-off-by: Roland Grunberg <rgrunber@redhat.com>
Signed-off-by: Roland Grunberg <rgrunber@redhat.com>
Signed-off-by: Roland Grunberg <rgrunber@redhat.com>
@rgrunber rgrunber requested a review from fbricon October 29, 2021 14:48
@rgrunber
Copy link
Copy Markdown
Member Author

rgrunber commented Oct 29, 2021

The remaining dependencies flagged by npm audit come from gulp, and we are at the latest version, 4.0.2. Though we update the underlying dependencies, if compatible, I think we have cases where the version of a dep in which the problem is fixed might be a major bump, whereas the dependency is only listed as compatible with gulp for minor bumps, so not sure if we can fix it without a new gulp version.

Articles like https://overreacted.io/npm-audit-broken-by-design/ are an interesting read.

@rgrunber rgrunber merged commit d711d06 into redhat-developer:master Nov 1, 2021
@rgrunber rgrunber deleted the audit-fix-update branch November 1, 2021 14:00
@rgrunber rgrunber added this to the Early November milestone Nov 1, 2021
@rgrunber rgrunber added debt dependencies Pull requests that update a dependency file labels Nov 1, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

debt dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant