[chore] address security-related issues & bump shelljs #1001
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Please select one of the following
Summary
While taking care of the dependabots alert, I noticed that the repo was in a bit of a weird state and there were a few extra yarn.lock that should have not been there in the first place (because the packages are part of the workspace as per root
package.json). This would result in dependabot still analizing them and creating "false" alarms against stale files.While doing so, I've also taken care of one of the last few alerts that were open about
shelljs; we could wait for it to land in main upstream (see facebook#33001) but since it's potentially relevant I decided to do it.Test Plan
CI passes