Skip to content

Conversation

@Bayheck
Copy link
Collaborator

@Bayheck Bayheck commented Feb 12, 2024

Purpose

Remove vulnerable lodash pick that was used by gulp-less version 4.

Approach

Updated version of gulp-less from version 4 to 5

References

https://github.com/DevExpress/testcafe/security/dependabot/24

Pre-Merge TODO

  • Write tests for your proposed changes
  • Make sure that existing tests do not fail

@need-response-app need-response-app bot added the STATE: Need response An issue that requires a response or attention from the team. label Feb 12, 2024
@Bayheck Bayheck removed the STATE: Need response An issue that requires a response or attention from the team. label Feb 12, 2024
@Aleksey28 Aleksey28 marked this pull request as ready for review February 16, 2024 13:32
@Aleksey28 Aleksey28 requested a review from aleks-pro as a code owner February 16, 2024 13:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants