Skip to content

Add word-wrap security advisory to audit allowlist#8679

Merged
aduth merged 2 commits intomainfrom
aduth-allowlist-word-wrap-advisory
Jun 28, 2023
Merged

Add word-wrap security advisory to audit allowlist#8679
aduth merged 2 commits intomainfrom
aduth-allowlist-word-wrap-advisory

Conversation

@aduth
Copy link
Contributor

@aduth aduth commented Jun 28, 2023

🛠 Summary of changes

Resolves security advisory notices affecting all builds on main, related to a a security advisory in the word-wrap dependency.

This is a temporary alternative to #8677 to allow builds to pass again. #8677 is a viable path forward, but requires more work to address issues with upgrades to the affected packages. This is enforced as temporary with an expiration of August 1.

The risk here is quite low due to how packages operate with optionator (see related comment gkz/optionator#44 (comment))

📜 Testing Plan

The audit_yarn_package exits with a successful exit code:

make audit_yarn_package
echo $?
# 0

changelog: Internal, Dependencies, Address security advisories
Copy link
Contributor

@jmax-gsa jmax-gsa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, as a temporary expedient.

@aduth aduth merged commit c875428 into main Jun 28, 2023
@aduth aduth deleted the aduth-allowlist-word-wrap-advisory branch June 28, 2023 16:16
@mdiarra3 mdiarra3 mentioned this pull request Jun 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants