Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do periodic security update (yarn audit) #1432

Open
wincent opened this issue Sep 8, 2020 · 37 comments
Open

Do periodic security update (yarn audit) #1432

wincent opened this issue Sep 8, 2020 · 37 comments

Comments

@wincent
Copy link
Contributor

wincent commented Sep 8, 2020

Similar to issues in other repos:

This issue will substitute these currently open dependabot PRs:

As always, will want to be extra careful with the node-sass update as it is very sensitive to NodeJS version in the environment.

Note that in this repo, too, we applied new config to limit Dependabot to one open PR at a time — it will still "spam" us, in the sense that if we close that PR it can open another, but at least we won't have up to 10 open PRs in the list at any one time.

More context on our policy here: https://github.com/liferay/liferay-frontend-guidelines/blob/master/general/security.md

@wincent
Copy link
Contributor Author

wincent commented Sep 8, 2020

Adding: #1433 (babel-eslint)

@wincent
Copy link
Contributor Author

wincent commented Sep 14, 2020

Adding: #1434 (react-dom)

@wincent
Copy link
Contributor Author

wincent commented Sep 15, 2020

Adding: #1435 (lodash, again)

@wincent
Copy link
Contributor Author

wincent commented Sep 21, 2020

Adding: #1436 (parallel-webpack)

@wincent
Copy link
Contributor Author

wincent commented Sep 28, 2020

Adding: #1438 (sinon)

@wincent
Copy link
Contributor Author

wincent commented Oct 5, 2020

Adding: #1440 (mocha)

@wincent
Copy link
Contributor Author

wincent commented Oct 13, 2020

Adding: #1441 (event-stream)

@wincent
Copy link
Contributor Author

wincent commented Oct 19, 2020

Adding: #1443 (eslint)

@wincent
Copy link
Contributor Author

wincent commented Oct 26, 2020

Adding: #1444 (webpack-dev-server)

@wincent
Copy link
Contributor Author

wincent commented Feb 15, 2021

Adding: #1463 (sinon, again)

@wincent
Copy link
Contributor Author

wincent commented Feb 22, 2021

Adding: #1464 (val-loader)

@wincent
Copy link
Contributor Author

wincent commented Mar 1, 2021

Adding: #1465 (webpack-dev-server, again).

@wincent
Copy link
Contributor Author

wincent commented Mar 8, 2021

Adding: #1468 (terser-webpack-plugin)

@wincent
Copy link
Contributor Author

wincent commented Mar 9, 2021

Adding: #1470 (elliptic)

@wincent
Copy link
Contributor Author

wincent commented Mar 15, 2021

Adding: #1471 (webpack)

@wincent
Copy link
Contributor Author

wincent commented Mar 22, 2021

Adding: #1472 (gulp-sass)

@wincent
Copy link
Contributor Author

wincent commented Mar 29, 2021

Adding: #1473 (prettier)

@wincent
Copy link
Contributor Author

wincent commented Mar 30, 2021

Adding: #1474 (y18n)

@wincent
Copy link
Contributor Author

wincent commented Apr 5, 2021

Adding: #1475 (webpack-merge)

@wincent
Copy link
Contributor Author

wincent commented Apr 12, 2021

Adding: #1476 (karma-sauce-launcher)

@wincent
Copy link
Contributor Author

wincent commented Apr 19, 2021

Adding: #1477 (del)

@wincent
Copy link
Contributor Author

wincent commented Apr 20, 2021

Adding: #1478 (ssri)

@wincent
Copy link
Contributor Author

wincent commented Apr 26, 2021

Adding: #1480 (bourbon)

@wincent
Copy link
Contributor Author

wincent commented May 5, 2021

Adding: #1481 (karma-webpack)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant