Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

unblock ci: update vuln deps + fix npm registry for snaps firefox #14437

Merged
merged 6 commits into from
Apr 14, 2022

Conversation

kumavis
Copy link
Member

@kumavis kumavis commented Apr 13, 2022

note: https://github.com/MetaMask/pm-security/issues/72

@kumavis kumavis requested a review from a team as a code owner April 13, 2022 20:28
@kumavis kumavis requested a review from digiwand April 13, 2022 20:28
@kumavis kumavis changed the title dep-audit-fix for async@2.6.3 Patch for vulnerable async@2.6.3 Apr 13, 2022
danjm
danjm previously approved these changes Apr 13, 2022
@kumavis
Copy link
Member Author

kumavis commented Apr 13, 2022

fixed upstream caolan/async#1828 (comment)

@kumavis kumavis dismissed stale reviews from danjm and FrederikBolding via bcee2c5 April 13, 2022 23:37
@kumavis
Copy link
Member Author

kumavis commented Apr 13, 2022

removed the patch, keeping the ignored vuln until the vuln is updated

@FrederikBolding
Copy link
Member

The yarn.lock file still contains the vulnerable version, you'll need to delete that and regenerate the lock file to update. We also don't need to add async as a direct dependency

kumavis and others added 3 commits April 13, 2022 13:50
* Use regular NPM registry for snaps on FF

* Fix linting

* Update app/scripts/metamask-controller.js

Co-authored-by: Shane <jonas.shane@gmail.com>

Co-authored-by: kumavis <kumavis@users.noreply.github.com>
Co-authored-by: Shane <jonas.shane@gmail.com>
@github-actions
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@kumavis kumavis changed the title Patch for vulnerable async@2.6.3 unblock ci: update vuln deps + fix npm registry Apr 14, 2022
@kumavis kumavis changed the title unblock ci: update vuln deps + fix npm registry unblock ci: update vuln deps + fix npm registry for snaps firefox Apr 14, 2022
@metamaskbot
Copy link
Collaborator

Builds ready [6ad6dfd]
Page Load Metrics (1368 ± 43 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint88154110189
domContentLoaded1214148513567436
load1214158713689043
domInteractive1214148513567436

@kumavis kumavis merged commit 0f44176 into develop Apr 14, 2022
@kumavis kumavis deleted the ci-dep-audit-fix branch April 14, 2022 03:28
@github-actions github-actions bot locked and limited conversation to collaborators Apr 14, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants