Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps-dev): pin tough-cookie version #739

Conversation

codecapitano
Copy link
Collaborator

Why

The last open dependabot security alert depedns on cypress.
We alreay updated cypress to the latest version, but it still pulls the vulnerable tough-cookie version.

For now we pin the version to the non-vulnerable one.

What

  • For now we pin the version via Yarn resolutions

Links

Checklist

  • Tests added
  • Changelog updated
  • Documentation updated

@codecapitano codecapitano added the dependencies Pull requests that update a dependency file label Nov 14, 2024
@codecapitano codecapitano force-pushed the add-resoution-to-force-non-vulnerable-version-of-tough-cookie branch from 749b4d1 to b908272 Compare November 14, 2024 15:51
@codecapitano codecapitano self-assigned this Nov 14, 2024
@codecapitano codecapitano merged commit a0a51f1 into main Nov 14, 2024
4 checks passed
@codecapitano codecapitano deleted the add-resoution-to-force-non-vulnerable-version-of-tough-cookie branch November 14, 2024 16:07
@codecapitano codecapitano changed the title chore(deps-dev): pin tough cookie version chore(deps-dev): pin tough-cookie version Nov 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant