Skip to content

Upgrade JS YAML package to resolve security advisory#8331

Merged
mitchellhenke merged 1 commit intomainfrom
mitchellhenke/yarn-yaml-update
May 3, 2023
Merged

Upgrade JS YAML package to resolve security advisory#8331
mitchellhenke merged 1 commit intomainfrom
mitchellhenke/yarn-yaml-update

Conversation

@mitchellhenke
Copy link
Contributor

🛠 Summary of changes

Resolves the following vulnerability:

yarn audit v1.22.19
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ high          │ Uncaught Exception in yaml                                   │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ yaml                                                         │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=2.2.2                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @18f/identity-normalize-yaml                                 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ @18f/identity-normalize-yaml > yaml                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://www.npmjs.com/advisories/1091871                     │
└───────────────┴──────────────────────────────────────────────────────────────┘
1 vulnerabilities found - Packages audited: 1068
Severity: 1 High

Copy link
Contributor

@zachmargolis zachmargolis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

changelog: Internal, Dependencies, Upgrade JS YAML package to resolve security advisory
@mitchellhenke mitchellhenke force-pushed the mitchellhenke/yarn-yaml-update branch from 54ab1e8 to e0a3e67 Compare May 3, 2023 21:28
@mitchellhenke
Copy link
Contributor Author

Admin merging because it is failing due to issues fixed in #8333

@mitchellhenke mitchellhenke merged commit 53e443b into main May 3, 2023
@mitchellhenke mitchellhenke deleted the mitchellhenke/yarn-yaml-update branch May 3, 2023 21:43
amirbey added a commit that referenced this pull request May 4, 2023
* LG-8948 Content changes only (#8312)

* Content changes

* fixing french translation

* changelog: User-facing changes, In-person proofing, update translations and content in prep for location and prepare step swap

* changelog: User-facing improvements, In-person proofing, update translations and content in prep for location and prepare step swap

* Update spanish translation

* Remove unnecessary bypass_sign_in calls (#8324)

* Remove unnecessary bypass_sign_in calls

changelog: Internal, Authentication, Remove unnecessary bypass_sign_in calls

* add comment describing usage of bypass_sign_in

* Ensure account deletion emails get sent even when emails are configured to send asynchronously (#8328)

changelog: Bug Fixes, Emails, Ensure account deletion emails get sent even when emails are configured to send asynchronously

* LG-9613 Update reporting CLI to allow monthly queries (#8318)

Co-authored-by: Zach Margolis <zachmargolis@users.noreply.github.com>

changelog: Internal, Update reporting options, Allows monthly authentication and IDV reports

* LG-9294 Rate limit for 'Verify your ID' must include a link back to SP (#8291)

* LG-9294 Rate limit for 'Verify your ID' must include a link back to SP

Add link to throttled error page enabled rate limited user to link back to SP using defined failure to proof url

changelog: User-Facing Improvements, Identity Verification, Rate limited user can link back to SP using  defined failure to proof url

* fix test for throttled failure to proof link

* lint fix

* fix rate limiting message for image upload controller

* fix paragraph hierarchy

* happy linting

* happier linting.

* fix single quote in spec

* create new i18n key for exiting idv due to failure

* update test to use idv.failure.exit.with_sp

* add status bar and cond'l sp_name failure exit message

* happy linting

* fix i18n unused keys error

* happy linting

* fix current step in spec

* check exit link without sp

* exit message in 1 line

* put exit msg in variable

* refactor exit text

* happy linting

* refactor back to original link test to satisfy unused keys test

---------

Co-authored-by: AmirReavis-Bey <amirreavis-bey@fcoh2j-wyp9w9mv.localdomain>

* LG-9386: 508 Complaince, Move from using window to tab. (#8317)

* changelog: User-Facing Improvements, 508 Issues, change language for default behavior to new tab instead of window

* update tab

* change name

* update to new tab

* fix erb lint

* french translation

* change to new tab

* fix html

* update spec

* add spanish translation

* LG-9297 Add Cancel Link (#8321)

* Adding Cancel option to review-issues of doc capture
* Adding test for not displaying sp option when reviewing errors
* Adding spec for displaying sp troubleshooting option
* Adding test for showSPOption to doc troubleshooting component
  
changelog: User-Facing Improvements, Document Capture, Adding cancel
to document capture error view

* LG-9438 | Fix bug with IPP redirect (#8303)

changelog: Internal, In-Person Proofing, Bugfix when verifying IPP data

Co-authored-by: Tomas Apodaca <Thomas.Apodaca@gsa.gov>

* test all review status in loop to avoid dupe code

* LG-9107 Redirect old hybrid text link to new controller (#8325)

* Redirect old hybrid text link to new controller

When a user saves a text link, we want them to be directed to the new code path rather than a 404,
even if the new path will tell them their session has expired.

changelog: Internal, Code quality, redirect from old hybrid flow text link to new code

* Remove FSM capture_doc tests that depend on old text link routes

Disabled tests will be removed by the big delete PR along with the rest of the code

* proofing_device_profiling enabled and disabled testing

* redefine contexts

* happy linting

* Upgrade JS YAML package to resolve security advisory (#8331)

changelog: Internal, Dependencies, Upgrade JS YAML package to resolve security advisory

* Fix javascript tests using updated new_window/new_tab content (#8333)

changelog: Bug Fixes, Testing, Fix tests using updated new_window/new_tab content

---------

Co-authored-by: Jack Ryan <jackryan@navapbc.com>
Co-authored-by: Mitchell Henke <mitchell.henke@gsa.gov>
Co-authored-by: Davida (she/they) <davida.marion@gsa.gov>
Co-authored-by: AmirReavis-Bey <amirreavis-bey@fcoh2j-wyp9w9mv.localdomain>
Co-authored-by: Malick Diarra <malick.diarra@gsa.gov>
Co-authored-by: Eric Gade <105373963+eric-gade@users.noreply.github.com>
Co-authored-by: Matt Wagner <mattwagner@navapbc.com>
Co-authored-by: Tomas Apodaca <Thomas.Apodaca@gsa.gov>
Co-authored-by: Sonia Connolly <sonia.connolly@gsa.gov>
@mdiarra3 mdiarra3 mentioned this pull request May 4, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants