Skip to content

Update JS flow dependencies to fix security issues #3296

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jul 8, 2019
Merged

Conversation

wing328
Copy link
Member

@wing328 wing328 commented Jul 8, 2019

PR checklist

  • Read the contribution guidelines.
  • Ran the shell script under ./bin/ to update Petstore sample so that CIs can verify the change. (For instance, only need to run ./bin/{LANG}-petstore.sh, ./bin/openapi3/{LANG}-petstore.sh if updating the {LANG} (e.g. php, ruby, python, etc) code generator or {LANG} client's mustache templates). Windows batch files can be found in .\bin\windows\. If contributing template-only or documentation-only changes which will change sample output, be sure to build the project first.
  • Filed the PR against the correct branch: master, 4.1.x, 5.0.x. Default: master.
  • Copied the technical committee to review the pull request if your PR is targeting a particular programming language.

Description of the PR

To address the following security alert:

Remediation
Upgrade mem to version 4.0.0 or later. For example:

"dependencies": {
  "mem": ">=4.0.0"
}
or…
"devDependencies": {
  "mem": ">=4.0.0"
}
Always verify the validity and compatibility of suggestions with your codebase.

@wing328
Copy link
Member Author

wing328 commented Jul 8, 2019

cc @CodeNinjai (2017/07) @frol (2017/07) @cliffano (2017/07)

also cc @ jaypea (the author of the Javascript (Flow types) generator)

@wing328 wing328 merged commit 3f9e374 into master Jul 8, 2019
@wing328 wing328 deleted the fix_js_security branch July 8, 2019 09:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant