Skip to content

Updated webpack-bundle-analyzer to eleminate ejs vulnnerability - #248

Merged
mamankhan99 merged 2 commits into
masterfrom
maman/fix-ejs-vulnerability
Jun 21, 2022
Merged

Updated webpack-bundle-analyzer to eleminate ejs vulnnerability#248
mamankhan99 merged 2 commits into
masterfrom
maman/fix-ejs-vulnerability

Conversation

@mamankhan99

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change
ejs 2.7.4 -> 3.1.7

Git issues:

chore(deps): update dependency node-forge to 1.3.0 [security]
chore(deps): update dependency minimist to 1.2.6 [security]

Pre-Merge Checklist:

Updated the version number in edx_proctoring/init.py and package.json if these changes are to be released.
Described your changes in CHANGELOG.rst
Confirmed Github reports all automated tests/checks are passing.
Approved by at least one additional reviewer.
Post-Merge:

Create a tag matching the new version number.

@openedx-webhooks

Copy link
Copy Markdown

Thanks for the pull request, @mamankhan99! I've created OSPR-6771 to keep track of it in JIRA, where we prioritize reviews. Please note that it may take us up to several weeks or months to complete a review and merge your PR.

Feel free to add as much of the following information to the ticket as you can:

  • supporting documentation
  • Open edX discussion forum threads
  • timeline information ("this must be merged by XX date", and why that is)
  • partner information ("this is a course on edx.org")
  • any other information that can help Product understand the context for the PR

All technical communication about the code itself will be done via the GitHub pull request interface. As a reminder, our process documentation is here.

Please let us know once your PR is ready for our review and all tests are green.

⚠️ We can't start reviewing your pull request until you've submitted a signed contributor agreement or indicated your institutional affiliation. Please see the CONTRIBUTING file for more information. If you've signed an agreement in the past, you may need to re-sign. See The New Home of the Open edX Codebase for details.

@natabene

natabene commented Jun 8, 2022

Copy link
Copy Markdown

@mamankhan99 Thank you for your PR, once your forms are processed, we will review it.

@mamankhan99 mamankhan99 reopened this Jun 13, 2022
@mamankhan99 mamankhan99 self-assigned this Jun 13, 2022
@natabene

Copy link
Copy Markdown

@mamankhan99 The check is green now, so the owning team will review soon.

@jmbowman
jmbowman requested a review from a team June 14, 2022 02:47
@davidjoy

Copy link
Copy Markdown
Contributor

I think this needs to be rebased on master to resolve the conflicts.

@mamankhan99

Copy link
Copy Markdown
Contributor Author

I think this needs to be rebased on master to resolve the conflicts.

Done!

@mamankhan99
mamankhan99 merged commit ecdea39 into master Jun 21, 2022
@mamankhan99
mamankhan99 deleted the maman/fix-ejs-vulnerability branch June 21, 2022 06:42
@edx-semantic-release

Copy link
Copy Markdown

🎉 This PR is included in version 11.0.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

open-source-contribution PR author is not from Axim or 2U released

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

6 participants