Skip to content

Maintenance: bump ip development dependency #2064

Closed
@dreamorosi

Description

@dreamorosi

Summary

The ip module, a transitive development dependency, brought in by lerna is vulnerable to GHSA-78xj-cgh5-2h22.

Since Dependabot seems to be not picking this up and opening a PR we should manually fix it.

Why is this needed?

So that we can remove the vulnerability from our development environment.

Which area does this relate to?

Other

Solution

Run npm audit fix and commit the new package-lock.json.

Acknowledgment

Future readers

Please react with 👍 and your use case to help us understand customer demand.

Metadata

Metadata

Assignees

Labels

completedThis item is complete and has been merged/shippedinternalPRs that introduce changes in governance, tech debt and chores (linting setup, baseline, etc.)

Type

No type

Projects

Status

Shipped

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions