-
Notifications
You must be signed in to change notification settings - Fork 2.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Theia] Upgrade version of less to 3.0.3 for fixing the vulnerability in cryptiles package #4441
[Theia] Upgrade version of less to 3.0.3 for fixing the vulnerability in cryptiles package #4441
Conversation
@@ -41,7 +41,7 @@ | |||
"font-awesome-webpack": "0.0.5-beta.2", | |||
"fs-extra": "^4.0.2", | |||
"ignore-loader": "^0.1.2", | |||
"less": "^2.7.2", | |||
"less": "^3.0.3", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@marcdumais-work CQ?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Not now. We decided to not hold back such changes until the foundation has decided how to go forward.
@vinayb21 please commit changes to yarn.lock file |
@kittaakos The build failed. |
Having the macOS and the Windows green builds, I think it is safe to merge this PR. But I leave this decision for the reviewer :) |
… in cryptiles package Signed-off-by: vinayb21 <[email protected]>
@@ -41,7 +41,7 @@ | |||
"font-awesome-webpack": "0.0.5-beta.2", | |||
"fs-extra": "^4.0.2", | |||
"ignore-loader": "^0.1.2", | |||
"less": "^2.7.2", | |||
"less": "^3.0.3", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Not now. We decided to not hold back such changes until the foundation has decided how to go forward.
Fixes: #4440