Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix FE dependabot issues #6

Closed
mwood77 opened this issue Feb 12, 2023 · 3 comments
Closed

Fix FE dependabot issues #6

mwood77 opened this issue Feb 12, 2023 · 3 comments

Comments

@mwood77
Copy link
Owner

mwood77 commented Feb 12, 2023

https://github.com/mwood77/winderoo/security/dependabot

@mwood77 mwood77 self-assigned this Feb 12, 2023
@mwood77 mwood77 added this to the v1.0 milestone Feb 12, 2023
@mwood77
Copy link
Owner Author

mwood77 commented Feb 12, 2023

f3d84c5

@mwood77
Copy link
Owner Author

mwood77 commented Feb 12, 2023

26a3386

bad version of ua-parser-js is used in karma & browser-sync

  1. https://github.com/mwood77/winderoo/security/dependabot/3
    macOS not dl'd, but can verify with (on macOS & linux)

  2. https://github.com/mwood77/winderoo/security/dependabot/1
    GHSA-89w7-5q45-r53w

@mwood77 mwood77 removed their assignment Feb 15, 2023
@mwood77
Copy link
Owner Author

mwood77 commented Feb 11, 2024

Dependabot will not open PRs to update packages

@mwood77 mwood77 closed this as completed Feb 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant