Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: update snyk policy to ignore one of non-applicable ELECTRON vuln and extend the expity of aggrid-community package #6047

Merged
merged 1 commit into from
Jul 22, 2024

Conversation

himanshusinghs
Copy link
Contributor

Description

This PR adds an ignore for SNYK-JS-ELECTRON-7443355 despite having a fix for this in main (#6041) because:

  1. Snyk does not yet recognise that Electron update 29.4.5 fixes the mentioned CVE
  2. The vulnerability does not apply to us

Have also extended the expiry of vuln related to aggridcommunity.

Checklist

Motivation and Context

  • Bugfix
  • New feature
  • Dependency update
  • Misc

Open Questions

Dependents

Types of changes

  • Backport Needed
  • Patch (non-breaking change which fixes an issue)
  • Minor (non-breaking change which adds functionality)
  • Major (fix or feature that would cause existing functionality to change)

…ln and extend the expity of aggrid-community package
@himanshusinghs himanshusinghs merged commit 06553db into main Jul 22, 2024
30 checks passed
@himanshusinghs himanshusinghs deleted the snyk-fixes branch July 22, 2024 08:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants