deps: force 3box>...>socket.io-parser>=4.0.5 (CVE-2022-2421) #16319
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
yarn audit
currently failing on prod/develop
.https://app.circleci.com/pipelines/github/MetaMask/metamask-extension/29636/workflows/60bece98-1128-4951-8184-031e5e3a46c7/jobs/771221/parallel-runs/0/steps/0-103
GHSA-qm95-pgcg-qqfq
Explanation
Not tested. (In particular, the upgrade contains one potentially breaking change: socketio/socket.io-parser@28d4f03).
If this change turns out to be breaking, I see two options to this PR:
GHSA-qm95-pgcg-qqfq
to.iyarc
.Related: #10608
Manual Testing Steps
Validate that 3box functionality is still intact after applying change.
Pre-Merge Checklist
+ If there are functional changes: