Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

lock event-stream to non-compromised version 3.3.4 - Prod unaffected // Test/Dev Security Fix #222

Merged
merged 3 commits into from
Nov 26, 2018

Conversation

phillipperalez
Copy link
Collaborator

@phillipperalez phillipperalez commented Nov 26, 2018

from: dominictarr/event-stream#115

Dependency libraries should have already updated this but let's make sure that the version is at a non-compromised version explicitly. This did not affect production as this is a nodemon vulnerability. We do not run nodemon for prod, only for test/dev commands.

@phillipperalez phillipperalez changed the title lock event-stream to non-compromised version lock event-stream to non-compromised version 4.0.1 Nov 26, 2018
Copy link
Contributor

@jdavidson jdavidson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

yarn.lock Outdated Show resolved Hide resolved
@phillipperalez phillipperalez changed the title lock event-stream to non-compromised version 4.0.1 lock event-stream to non-compromised version 3.3.4 Nov 26, 2018
@phillipperalez phillipperalez changed the title lock event-stream to non-compromised version 3.3.4 lock event-stream to non-compromised version 3.3.4 - Prod unaffected // Test/Dev Security Fix Nov 26, 2018
@phillipperalez phillipperalez merged commit 9e63bb7 into master Nov 26, 2018
@phillipperalez phillipperalez deleted the lock-event-stream-version branch November 26, 2018 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants