Closed
Description
Summary
The ip
module, a transitive development dependency, brought in by lerna
is vulnerable to GHSA-78xj-cgh5-2h22.
Since Dependabot seems to be not picking this up and opening a PR we should manually fix it.
Why is this needed?
So that we can remove the vulnerability from our development environment.
Which area does this relate to?
Other
Solution
Run npm audit fix
and commit the new package-lock.json
.
Acknowledgment
- This request meets Powertools for AWS Lambda (TypeScript) Tenets
- Should this be considered in other Powertools for AWS Lambda languages? i.e. Python, Java, and .NET
Future readers
Please react with 👍 and your use case to help us understand customer demand.
Metadata
Metadata
Assignees
Labels
Type
Projects
Status
Shipped