Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

devDeps: bump and align devDependencies #19194

Merged
merged 7 commits into from
Jun 15, 2023

Conversation

legobeat
Copy link
Contributor

@legobeat legobeat commented May 18, 2023

Pre-merge reviewer checklist

  • Manual testing (e.g. pull and build branch, run in browser, test code being changed)
  • PR is linked to the appropriate GitHub issue
  • IF this PR fixes a bug in the release milestone, add this PR to the release milestone

@github-actions
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@legobeat legobeat force-pushed the devdeps-bumps branch 4 times, most recently from 12e9584 to 912ed48 Compare May 20, 2023 00:19
@socket-security
Copy link

socket-security bot commented May 20, 2023

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: madge@6.1.0, detective-postcss@6.1.3, stream-to-array@2.3.0, any-promise@1.3.0

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

@legobeat

This comment was marked as resolved.

@legobeat

This comment was marked as resolved.

@legobeat legobeat marked this pull request as ready for review May 20, 2023 00:27
@legobeat legobeat requested review from a team as code owners May 20, 2023 00:27
@legobeat legobeat requested a review from georgewrmarshall May 20, 2023 00:27
@legobeat legobeat added area-buildSystem related to our build system dependencies Pull requests that update a dependency file labels May 20, 2023
@legobeat legobeat force-pushed the devdeps-bumps branch 5 times, most recently from a59e82b to ac57cec Compare May 30, 2023 21:41
@legobeat legobeat force-pushed the devdeps-bumps branch 7 times, most recently from ea58333 to 748484d Compare May 31, 2023 21:25
@codecov
Copy link

codecov bot commented May 31, 2023

Codecov Report

Merging #19194 (4e4dae3) into develop (40d1df1) will decrease coverage by 0.18%.
The diff coverage is n/a.

❗ Current head 4e4dae3 differs from pull request most recent head e1396f0. Consider uploading reports for the commit e1396f0 to get more accurate results

@@             Coverage Diff             @@
##           develop   #19194      +/-   ##
===========================================
- Coverage    70.47%   70.28%   -0.18%     
===========================================
  Files          972      973       +1     
  Lines        37277    37250      -27     
  Branches      9635     9603      -32     
===========================================
- Hits         26268    26181      -87     
- Misses       11009    11069      +60     

see 27 files with indirect coverage changes

@legobeat legobeat force-pushed the devdeps-bumps branch 2 times, most recently from e891aa4 to 44725ff Compare May 31, 2023 22:39
@legobeat legobeat force-pushed the devdeps-bumps branch 2 times, most recently from f91cb16 to c9f3ea6 Compare June 5, 2023 17:43
@legobeat
Copy link
Contributor Author

legobeat commented Jun 5, 2023

@SocketSecurity ignore madge@6.1.0

we cool

@socket-security
Copy link

socket-security bot commented Jun 6, 2023

New and updated dependency changes detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives1 Size Publisher
gh-pages ⬆️ 3.2.3...5.0.0 None +1/-1 168 kB tschaub
madge ⬆️ 5.0.2...6.1.0 None +10/-5 792 kB kamiazya
dependency-tree ⬆️ 8.1.2...10.0.9 None +22/-0 40.6 MB xhmikosr

🚮 Removed packages: del@3.0.0

Footnotes

  1. https://docs.socket.dev

@legobeat
Copy link
Contributor Author

legobeat commented Jun 6, 2023

@SocketSecurity ignore stackframe@1.3.4

@legobeat legobeat force-pushed the devdeps-bumps branch 5 times, most recently from a701d11 to cb198a9 Compare June 8, 2023 06:44
mcmire
mcmire previously approved these changes Jun 8, 2023
Copy link
Contributor

@mcmire mcmire left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

@legobeat
Copy link
Contributor Author

legobeat commented Jun 9, 2023

Broke out @whitespace-se/storybook-addon-html to #19539.

@legobeat legobeat changed the title devDeps: bump and align devdepencies devDeps: bump and align devDependencies Jun 9, 2023
@legobeat legobeat merged commit f286d16 into MetaMask:develop Jun 15, 2023
@github-actions github-actions bot locked and limited conversation to collaborators Jun 15, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
area-buildSystem related to our build system dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants