Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Test explicit overriding ajv dependency for moderate risk dependency #281

Merged
merged 1 commit into from
Jan 9, 2023

Conversation

aj-stein-nist
Copy link
Collaborator

@aj-stein-nist aj-stein-nist commented Jan 9, 2023

Committer Notes

Test override fix on GHSA-8gh8-hqwg-xf34.

All Submissions:

  • Have you followed the guidelines in our Contributing document?
  • Have you checked to ensure there aren't other open Pull Requests for the same update/change?
  • Have you squashed any non-relevant commits and commit messages? [instructions]
  • Do all automated CI/CD checks pass?

Changes to Core Features:

  • Have you added an explanation of what your changes do and why you'd like us to include them?
  • Have you written new tests for your core changes, as applicable?
  • Have you included examples of how to use your new feature(s)?
  • Have you updated all website](https://pages.nist.gov/metaschema) and readme documentation affected by the changes you made? Changes to the website can be made in the website/content directory of your branch.

@aj-stein-nist aj-stein-nist self-assigned this Jan 9, 2023
@aj-stein-nist aj-stein-nist marked this pull request as ready for review January 9, 2023 16:51
@aj-stein-nist
Copy link
Collaborator Author

@david-waltermire-nist, here is the override patch as requested. It works with local commands from the init-validate-content.sh script so it seems to work without issue, as ajv-validator/ajv-cli#227 is blocked with other dependency and CI/CD issues in another PR, so it seems they know they can make a clean patch as well.

@aj-stein-nist aj-stein-nist changed the title Test explicit overriding ajv dependency for moderate dependency Test explicit overriding ajv dependency for moderate risk dependency Jan 9, 2023
@david-waltermire david-waltermire merged commit ba9bdc5 into main Jan 9, 2023
@david-waltermire david-waltermire deleted the chore-patch-ghsa-8gh8-hqwg-xf34 branch January 9, 2023 19:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

2 participants