resolve uglify-js CVEs#40
Open
mcandre wants to merge 1 commit intofishbar:masterfrom
mcandre:update-uglify-js
Open
resolve uglify-js CVEs#40mcandre wants to merge 1 commit intofishbar:masterfrom mcandre:update-uglify-js
mcandre wants to merge 1 commit intofishbar:masterfrom
mcandre:update-uglify-js
Conversation
gpolitis
added a commit
to jitsi/sdp-interop
that referenced
this pull request
Jul 14, 2020
jscoverage pulls some dev dependencies that have known CVEs (debug and uglify-js). There are PRs [1], [2] that fix the CVEs but the project seems to be unmaintained. Furthermore, the jscoverage tool is in a broken state at the moment, most likely because it doesn't understand ES6 (but I could be wrong about that). For these two reason I'm booting it from the project and we can re-evaluate if anything ever changes. [1]: fishbar/jscoverage#40 [2]: fishbar/jscoverage#41
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Update uglify-js, while keeping
npm test1passing, in order to resolve vulnerability reports associated with earlier editions of uglify-js.