Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add word-wrap security advisory to audit allowlist #8679

Merged
merged 2 commits into from
Jun 28, 2023

Conversation

aduth
Copy link
Member

@aduth aduth commented Jun 28, 2023

馃洜 Summary of changes

Resolves security advisory notices affecting all builds on main, related to a a security advisory in the word-wrap dependency.

This is a temporary alternative to #8677 to allow builds to pass again. #8677 is a viable path forward, but requires more work to address issues with upgrades to the affected packages. This is enforced as temporary with an expiration of August 1.

The risk here is quite low due to how packages operate with optionator (see related comment gkz/optionator#44 (comment))

馃摐 Testing Plan

The audit_yarn_package exits with a successful exit code:

make audit_yarn_package
echo $?
# 0

changelog: Internal, Dependencies, Address security advisories
Copy link
Contributor

@jmax-gsa jmax-gsa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, as a temporary expedient.

@aduth aduth merged commit c875428 into main Jun 28, 2023
3 checks passed
@aduth aduth deleted the aduth-allowlist-word-wrap-advisory branch June 28, 2023 16:16
@mdiarra3 mdiarra3 mentioned this pull request Jun 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants