Skip to content

chore: resolve helper package audit advisories#1190

Open
bridgelol wants to merge 1 commit into
PrismarineJS:masterfrom
bridgelol:agent/fix-helper-vulnerabilities
Open

chore: resolve helper package audit advisories#1190
bridgelol wants to merge 1 commit into
PrismarineJS:masterfrom
bridgelol:agent/fix-helper-vulnerabilities

Conversation

@bridgelol
Copy link
Copy Markdown

Updates GitHub helper/tool package manifests so generated npm audit lockfiles report zero vulnerabilities.\n\nChanges:\n- add overrides for vulnerable mocha/serialize-javascript and protodef-yaml/showdown transitives in tools/js\n- update gh-helpers and force patched CommonJS-compatible @actions/@octokit/undici versions for the helper bot\n\nVerification:\n- npm audit --json in tools/js\n- npm audit --json in .github/helper-bot\n- npm run lint in tools/js\n- npm test in tools/js (1742 passing, 1 pending)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant