Skip to content
This repository has been archived by the owner on Jan 18, 2022. It is now read-only.

Update dependencies to address high sev vulnerabilities #149

Merged
merged 2 commits into from
Apr 23, 2021

Conversation

vdamle
Copy link
Contributor

@vdamle vdamle commented Apr 6, 2021

  • downstream builds that use this package fail due to high severity
    vulnerabilities
  • update gitignore to include package-lock.json and delete the file in
    git

Verified that tests pass locally by running npm test

* downstream builds that use this package fail due to high severity
vulnerabilities
* update gitignore to include package-lock.json and delete the file in
git
@CLAassistant
Copy link

CLAassistant commented Apr 6, 2021

CLA assistant check
All committers have signed the CLA.

Copy link
Contributor

@macfarla macfarla left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

apologies for the delay on our end - this looks good except that we need the package-lock.json for the CI build process.

turns out it's required for builds to work
@vdamle
Copy link
Contributor Author

vdamle commented Apr 22, 2021

thanks for the feedback, @macfarla . I've restored package-lock.json and looks like the CI build is passing now.

Copy link
Contributor

@macfarla macfarla left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@macfarla macfarla merged commit 7db4fa7 into Consensys:master Apr 23, 2021
@macfarla
Copy link
Contributor

Thanks for the contribution!

@vdamle vdamle deleted the update-deps branch April 23, 2021 19:28
@vdamle
Copy link
Contributor Author

vdamle commented Apr 27, 2021

@macfarla - Is there a timeline for when a release with the latest changes will be cut?

@macfarla macfarla mentioned this pull request Apr 30, 2021
@macfarla
Copy link
Contributor

@vdamle 0.11.0 released!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants