Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade react-live version to remove dependency on dom-iterator #2985

Merged
merged 1 commit into from
Nov 15, 2024

Conversation

hstonec
Copy link
Contributor

@hstonec hstonec commented Nov 15, 2024

Motivation

We got reported that dom-iterator:1.0.0 is a vulnerable dependency. However, it is already the latest version and the only package depends on it is react-live. So upgrading react-live to remove dom-iterator from the dependency.

Have you read the Contributing Guidelines on pull requests?

Yes

Test Plan

yarn
yarn start

Then verified the website works as expected.

Related Issues and PRs

N/A

@facebook-github-bot facebook-github-bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Nov 15, 2024
Copy link
Contributor

@Sanjay-Ganeshan Sanjay-Ganeshan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@hstonec hstonec merged commit bc7e323 into main Nov 15, 2024
24 checks passed
@hstonec hstonec deleted the fix-vul-11-15 branch November 15, 2024 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants