Skip to content

chore: update to resolve sec vulnerability in node-forge - #3929

Merged
Aaron Wentzel (awentzel) merged 2 commits into
masterfrom
users/awentzel/selfsigned
Sep 21, 2020
Merged

chore: update to resolve sec vulnerability in node-forge#3929
Aaron Wentzel (awentzel) merged 2 commits into
masterfrom
users/awentzel/selfsigned

Conversation

@awentzel

Copy link
Copy Markdown
Collaborator

Description

Webpack depends on selfsigned which has a vulnerability in 1.10.7. This updates webpack across our solution to use the latest and resolves this vulnerability. Webpack does upgrade to a safe version, with this PR, after running yarn.

Motivation & context

Resolve security vulnerability documented https://github.com/microsoft/fast/network/alert/yarn.lock/node-forge/open and the fix documented webpack/webpack-dev-server#2740

Issue type checklist

  • Chore: A change that does not impact distributed packages.
  • Bug fix: A change that fixes an issue, link to the issue above.
  • New feature: A change that adds functionality.

Is this a breaking change?

  • This change causes current functionality to break.

Adding or modifying component(s) in @microsoft/fast-components checklist

Process & policy checklist

  • I have added tests for my changes.
  • I have tested my changes.
  • I have updated the project documentation to reflect my changes.
  • I have read the CONTRIBUTING documentation and followed the standards for this project.

@awentzel
Aaron Wentzel (awentzel) merged commit 2575bb7 into master Sep 21, 2020
@awentzel
Aaron Wentzel (awentzel) deleted the users/awentzel/selfsigned branch September 21, 2020 20:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore Maintenance or non-code work compliance:security Security-related work.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants