Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(common): next bump #176

Merged
merged 3 commits into from
Dec 26, 2024
Merged

feat(common): next bump #176

merged 3 commits into from
Dec 26, 2024

Conversation

kirill-ivanovvv
Copy link
Contributor

closes #168

вот этот момент не понимаю как закрыть. пакет только в yarn.lock мелькает

@kirill-ivanovvv kirill-ivanovvv self-assigned this Dec 26, 2024
@Nelfimov
Copy link
Contributor

вот этот момент не понимаю

это какой?

@Nelfimov Nelfimov merged commit b9518d5 into master Dec 26, 2024
4 of 6 checks passed
@Nelfimov Nelfimov deleted the fix/dependabot branch December 26, 2024 15:53
@kirill-ivanovvv
Copy link
Contributor Author

вот этот момент не понимаю

это какой?

rollup & node-fetch

https://github.com/torin-asakura/shdvor/security/dependabot/24
https://github.com/torin-asakura/shdvor/security/dependabot/22

@Nelfimov
Copy link
Contributor

вот этот момент не понимаю

это какой?

rollup & node-fetch

DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS node-fetch forwards secure headers to untrusted sites

Если они не отслеживаются через yarn why то можно попробовать снести yarn.lock и пересобрать его. Либо запустить yarn dedupe

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Фикс ошибок dependabot
2 participants