Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): Remove serve dev dependency #7967

Merged
merged 1 commit into from
Sep 16, 2024
Merged

fix(security): Remove serve dev dependency #7967

merged 1 commit into from
Sep 16, 2024

Conversation

jordanvn
Copy link
Member

Description of changes:

  • Removed dev dependency serve
    • serve is not being used in repository
    • Resolves a security vulnerability reported by dependabot for path-to-regexp
      • Has been included via serve -> serve-handler -> path-to-regexp

Related GitHub issue #, if available:

https://github.com/aws-amplify/docs/security/dependabot/77

Instructions

If this PR should not be merged upon approval for any reason, please submit as a DRAFT

Which product(s) are affected by this PR (if applicable)?

  • amplify-cli
  • amplify-ui
  • amplify-studio
  • amplify-hosting
  • amplify-libraries

Which platform(s) are affected by this PR (if applicable)?

  • JS
  • Swift
  • Android
  • Flutter
  • React Native

Please add the product(s)/platform(s) affected to the PR title

Checks

  • Does this PR conform to the styleguide?

  • Does this PR include filetypes other than markdown or images? Please add or update unit tests accordingly.

  • Are any files being deleted with this PR? If so, have the needed redirects been created?

  • Are all links in MDX files using the MDX link syntax rather than HTML link syntax?

    ref: MDX: [link](https://docs.amplify.aws/)
    HTML: <a href="https://docs.amplify.aws/">link</a>

When this PR is ready to merge, please check the box below

  • Ready to merge

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@jordanvn jordanvn requested a review from a team as a code owner September 16, 2024 16:19
@jordanvn jordanvn merged commit e53ca20 into main Sep 16, 2024
12 checks passed
@jordanvn jordanvn deleted the remove-serve-dep branch September 16, 2024 19:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants