Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve all npm vulnerabilities #108

Merged
merged 2 commits into from
Jan 19, 2024
Merged

Resolve all npm vulnerabilities #108

merged 2 commits into from
Jan 19, 2024

Conversation

JstnMcBrd
Copy link
Contributor

Fixed

  • Resolved all npm vulnerabilities using npm audit fix
  • Fixed axios vulnerability with override

pm2 relies on an outdated version of axios with a vulnerability. It appears the owner of pm2 has gone inactive and the project is no longer maintained. An override is the suggested solution from the community.

In the long term, it may be worthwhile to replace pm2.

@JstnMcBrd JstnMcBrd added the bugfix A PR that fixes something that wasn't working label Jan 15, 2024
@JstnMcBrd JstnMcBrd requested a review from a team January 15, 2024 08:01
@JstnMcBrd JstnMcBrd self-assigned this Jan 15, 2024
@JstnMcBrd JstnMcBrd merged commit 79e3740 into main Jan 19, 2024
4 checks passed
@JstnMcBrd JstnMcBrd deleted the mcb/vulns branch January 19, 2024 01:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bugfix A PR that fixes something that wasn't working
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants