chore: resolve vulnerable sub-dependencies #5509
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Pull Request
📖 Description
Updates packages which have dependencies on the vulnerable
colorsNPM package:rollup-plugin-filesizefrom8.0.2to9.1.2http-serverfrom0.12.1to14.1.0faviconsfrom6.1.0to6.2.2colorsto1.4.0forkarmain the resolutions fieldcolorsto1.4.0forfaviconsin the resolutions field👩💻 Reviewer Notes
Some packages are still vulnerable:
Packages which rely on a stricter version range and are less vulnerable:
~1.2.1range [all projects] Remove all dependencies on the "colors" NPM package rushstack#3147)^1.1.2range fix: Replace colors with chalk to fix infinite loop. cli-table/cli-table3#250)📑 Test Plan
Our project does not use the
colorspackage directly so everything should continue to behave as expected.✅ Checklist
General
$ yarn change