Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 2.x] [CVE] Bump tsd to 0.21.0 #1786

Merged
merged 1 commit into from
Jun 24, 2022

Conversation

opensearch-trigger-bot[bot]
Copy link
Contributor

Backport d1cfe78 from #1770

- Partially addresses: CVE-2022-33987
- bumps `tsd` dependencies from `0.16.0` to `0.21.0` (latest)
  - [`tsd` release changelog](https://github.com/SamVerschueren/tsd/releases)
  - Breaking changes:
    - `0.17.0` includes "Require Node.js 12" - this is not a breaking change as we've already update to node `14.19.1`

`tsd v0.17.0` removes dependency chain:
- `update-notifier`
- `latest-version`
- `package-json`
- `got`

Partial fix for #1764

Signed-off-by: Josh Romero <[email protected]>
(cherry picked from commit d1cfe78)
@opensearch-trigger-bot opensearch-trigger-bot bot requested a review from a team as a code owner June 23, 2022 19:11
@joshuarrrr joshuarrrr merged commit 53bd77b into 2.x Jun 24, 2022
@joshuarrrr joshuarrrr deleted the backport/backport-1770-to-2.x branch June 24, 2022 16:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants