Skip to content

Conversation

e-fisher
Copy link
Contributor

What?

Bump dashboard packages to address CVEs. Added resolutions to package.json to install package versions where CVEs are fixed. It resolves all reported CVEs except low severity tsup package warning. It doesn't have a fixed version suggestion and has no SLO, so I didn't invest time into fixing this and leaving as is for now.

Why?

Checklist

  • I have performed a self-review of my code.
  • I have added tests for my changes.
  • I have run linter locally (mage lint) and all checks pass.
  • I have run tests locally (mage test) and all tests pass.
  • I have commented on my code, particularly in hard-to-understand areas.

Related PR(s)/Issue(s)

Closes #234

@e-fisher e-fisher requested a review from a team as a code owner August 26, 2025 07:21
@e-fisher e-fisher requested review from szkiba and removed request for a team August 26, 2025 07:21
@CLAassistant
Copy link

CLAassistant commented Aug 26, 2025

CLA assistant check
All committers have signed the CLA.

Copy link
Contributor

@szkiba szkiba left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM
Thank you for your contribution

@szkiba szkiba merged commit 25fa5aa into master Aug 26, 2025
31 checks passed
@szkiba szkiba deleted the task/fix-cves branch August 26, 2025 08:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Fix CVEs
3 participants