Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update pg to 8.4.0 #110

Merged
merged 1 commit into from
Jul 25, 2023
Merged

Update pg to 8.4.0 #110

merged 1 commit into from
Jul 25, 2023

Conversation

LAKSHMIRPILLAI
Copy link
Contributor

What does this change?

Update [email protected] from 8.3.0 as it's transitive dependency [email protected] came up as a 'High Risk' vulnerability in Snyk

image

@LAKSHMIRPILLAI LAKSHMIRPILLAI marked this pull request as ready for review July 25, 2023 09:39
@LAKSHMIRPILLAI LAKSHMIRPILLAI changed the title Updated pg to 8.4.0 Update pg to 8.4.0 Jul 25, 2023
@emdash-ie
Copy link
Contributor

emdash-ie commented Jul 25, 2023

We had a look at this together and we’re confused about it: why is Snyk reporting that we’re depending on version 7.18.2 of pg? It’s not visible in our yarn.lock anywhere, and a newer version (8.8) is, so it seems like it should be fine. We’ve agreed to merge the PR and see if that causes Snyk to update – we’re not sure exactly how the update process is supposed to work.

@LAKSHMIRPILLAI LAKSHMIRPILLAI merged commit f0e9c50 into main Jul 25, 2023
1 check passed
@LAKSHMIRPILLAI LAKSHMIRPILLAI deleted the lp-update-pg-semver branch July 25, 2023 11:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants