Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MLPAB-504: Fix CVE 2022 3517 #221

Merged
merged 3 commits into from
Dec 1, 2022
Merged

MLPAB-504: Fix CVE 2022 3517 #221

merged 3 commits into from
Dec 1, 2022

Conversation

acsauk
Copy link
Contributor

@acsauk acsauk commented Dec 1, 2022

Purpose

Fixes https://nvd.nist.gov/vuln/detail/CVE-2022-3517. Dropping cypress-parallel until the package supports mocha v9 - see tnicola/cypress-parallel#134.

I've also set all our JS deps to patch to the next minor version - happy to be challenged on this if there are fears about chain attacks but given our fairly limited dependencies the risk didn't seem too high.

Fixes MLPAB-504

@codecov
Copy link

codecov bot commented Dec 1, 2022

Codecov Report

Base: 94.55% // Head: 94.55% // No change to project coverage 👍

Coverage data is based on head (49a62e8) compared to base (753ee56).
Patch has no changes to coverable lines.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #221   +/-   ##
=======================================
  Coverage   94.55%   94.55%           
=======================================
  Files          53       53           
  Lines        3088     3088           
=======================================
  Hits         2920     2920           
  Misses        130      130           
  Partials       38       38           
Flag Coverage Δ
unittests 94.55% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

☔ View full report at Codecov.
📢 Do you have feedback about the report comment? Let us know in this issue.

@acsauk acsauk marked this pull request as ready for review December 1, 2022 15:19
@acsauk acsauk requested a review from a team as a code owner December 1, 2022 15:19
@acsauk acsauk merged commit 09dd658 into main Dec 1, 2022
@acsauk acsauk deleted the fix_CVE-2022-3517 branch December 1, 2022 15:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants