Skip to content

Conversation

@radium-v
Copy link
Collaborator

Pull Request

📖 Description

Updates packages which have dependencies on the vulnerable colors NPM package:

  • rollup-plugin-filesize from 8.0.2 to 9.1.2
  • updates http-server from 0.12.1 to 14.1.0
  • updates favicons from 6.1.0 to 6.2.2
  • locks colors to 1.4.0 for karma in the resolutions field
  • locks colors to 1.4.0 for favicons in the resolutions field

👩‍💻 Reviewer Notes

Some packages are still vulnerable:

Packages which rely on a stricter version range and are less vulnerable:

📑 Test Plan

Our project does not use the colors package directly so everything should continue to behave as expected.

✅ Checklist

General

  • I have included a change request file using $ yarn change
  • I have added tests for my changes.
  • I have tested my changes.
  • I have updated the project documentation to reflect my changes.
  • I have read the CONTRIBUTING documentation and followed the standards for this project.

Copy link
Member

@chrisdholt chrisdholt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @radium-v!

@radium-v radium-v merged commit af847f2 into master Jan 10, 2022
@radium-v radium-v deleted the users/jokreitl/resolve-colors branch January 10, 2022 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants