Skip to content

chore(security): fixed 5 vulnerabilities#599

Merged
jimthedev merged 2 commits into
commitizen:masterfrom
Berkmann18:dev
Jul 17, 2019
Merged

chore(security): fixed 5 vulnerabilities#599
jimthedev merged 2 commits into
commitizen:masterfrom
Berkmann18:dev

Conversation

@Berkmann18

Copy link
Copy Markdown
Contributor

I fixed 5 (out of 13) vulnerabilities, all of which were caused by the semantic-release's version used prior to this PR.
The 8 others are caused by codecov which are all only affecting the development so I left that aside (unless someone wants me to go ahead and try to fix those too).

Also, after running a dependency check (with npm-check -u), I've noticed that there were the following non-breaking updates which I think would be a good idea to do:

  • Patch updates: fs-extra, inquirer, nodemon [dev]
  • Minor updates (all dev dependencies): @babel/cli, @babel/core, @babel/preset-env, chai, eslint, nyc and semver.

@jimthedev

Copy link
Copy Markdown
Member

Thanks for doing this. It looks good except that on Windows the builds are breaking which is the same we were seeing when attempting this upgrade.

@Berkmann18

Berkmann18 commented Dec 30, 2018

Copy link
Copy Markdown
Contributor Author

@jimthedev Have you found out why it was breaking?
And which version bump broke it?

@Berkmann18 Berkmann18 changed the title chore(security) Fixed 5 vulnerabilities chore(security): Fixed 5 vulnerabilities Jan 14, 2019
@Berkmann18 Berkmann18 changed the title chore(security): Fixed 5 vulnerabilities chore(security): fixed 5 vulnerabilities Jan 14, 2019
@jimthedev

Copy link
Copy Markdown
Member

Looks like it was the windows builds. Something like Cmd.exe existed with code 1 but then I didn't catch the actual error and the build is gone now. If you rebase it should happen again.

Fixed 5 vulnerabilities found in `semantic-release`.
Rebased from the master branch an fixed additional vulnerabilities
@jimthedev jimthedev merged commit b24eade into commitizen:master Jul 17, 2019
@commitizen-bot

Copy link
Copy Markdown

🎉 This PR is included in version 3.1.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants