Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve immer security alert #315

Closed
jessex opened this issue Jan 22, 2021 · 6 comments
Closed

Resolve immer security alert #315

jessex opened this issue Jan 22, 2021 · 6 comments
Assignees
Labels
Team: Glitter Issues/Epics owned by Glitter (public data efforts)

Comments

@jessex
Copy link
Member

jessex commented Jan 22, 2021

What needs to be done? Why does it need to be done?
Resolve the HIGH severity immer security alert: https://github.com/Recidiviz/public-dashboard/security/dependabot/yarn.lock/immer/open

Additional context
This should be resolved within the week of January 25, 2021.

@jessex jessex added the Team: Glitter Issues/Epics owned by Glitter (public data efforts) label Jan 22, 2021
@jessex
Copy link
Member Author

jessex commented Jan 22, 2021

@macfarlandian new security alert for you. Since it's HIGH severity, we want to resolve it next week. Thanks!

@macfarlandian
Copy link
Collaborator

@jessex this alert seems to have resolved on its own? I'm not able to find what it was objecting to, nor do I see any recent version changes to that dependency in master, so maybe there was a blip in Dependabot or something?

@jessex
Copy link
Member Author

jessex commented Jan 26, 2021

You're right. Was there a recent commit that may have changed the dependency graph? If not, then the CVE itself must have been updated such that it is no longer a vulnerability for us. FWIW, it remains active in the supervision-success-component repository here: https://github.com/Recidiviz/supervision-success-component/security/dependabot/yarn.lock/immer/open

@macfarlandian
Copy link
Collaborator

oh thanks, that helps! Oddly, we still have the very same transitive dependency on the same version of immer, so I don't know why we aren't getting the alert here.

Over at the CRA repo they say there is no actual runtime vulnerability, which is good, but they also have a patch PR open. If that gets merged we ought to be able to upgrade react-scripts in any of our projects to resolve it.

@macfarlandian
Copy link
Collaborator

@jessex do we want to keep this ticket open while we wait for an upstream update, or is this a wontfix now that the security alert is no longer active?

@jessex
Copy link
Member Author

jessex commented Feb 5, 2021

With the security alert no longer active, we should close this and reopen this or a new issue if and when this becomes an active alert again. Thanks, Ian!

@jessex jessex closed this as completed Feb 5, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team: Glitter Issues/Epics owned by Glitter (public data efforts)
Projects
None yet
Development

No branches or pull requests

3 participants