Skip to content

fix: package.json, package-lock.json & .snyk to reduce vulnerabilities#1653

Closed
Kirobi92 wants to merge 1 commit intoipfs:masterfrom
Kirobi92:snyk-fix-64d5794875a96adf9225a21bf63fc2cd
Closed

fix: package.json, package-lock.json & .snyk to reduce vulnerabilities#1653
Kirobi92 wants to merge 1 commit intoipfs:masterfrom
Kirobi92:snyk-fix-64d5794875a96adf9225a21bf63fc2cd

Conversation

@Kirobi92
Copy link

The following vulnerabilities are fixed with an upgrade:

The following vulnerabilities are fixed with a Snyk patch:

@lidel
Copy link
Member

lidel commented Sep 22, 2020

Thank you for submitting the PR, but I'm not able to merge it, because it introduces vendor-specific patching via a thirdparty tool.

In IPFS repos we usually bump dependencies before each release, and have github dependency check enabled, so adding Snyk would only increase noise and bring the opposite effect.

That being said, I may be wrong: let me know if I am missing some deeper point or added value here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants