Package upgrades to fix vulnerabilities #42
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Upgrades packages to fix security vulnerabilities. There are currently 3 vulnerabilities that haven't been fixed in this. One is moderate with the
request
package, and another 2 critical in thevm2
package. These are sub dependencies used by some packages we use.I've looked into these getting fixed, and with the
vm2
issues, there is an issue open right now awaiting merge which ensures we use the latest version which has the security fix included. See here.The
request
issue looks a little less likely, although there is a PR awaiting merge, it seems that the package is no longer supported. I don't think there's anything we can do with this as its included byfirebase-tools
. See PR here