Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update high vulnerability dependencies #16218

Closed
5 tasks done
edmundito opened this issue Sep 1, 2022 · 9 comments
Closed
5 tasks done

Update high vulnerability dependencies #16218

edmundito opened this issue Sep 1, 2022 · 9 comments
Assignees
Labels
area/frontend Related to the Airbyte webapp

Comments

@edmundito
Copy link
Contributor

edmundito commented Sep 1, 2022

Merge PRs related to high security vulnerabilities found by dependabot and snyk:

For specific dependencies that are difficult or time-consuming to upgrade, create a new issue for each in the product backlog describing the challenges you encountered.

Related: #10573

@edmundito edmundito added the area/frontend Related to the Airbyte webapp label Sep 1, 2022
@octavia-squidington-iii
Copy link
Collaborator

cc @airbytehq/frontend

@krishnaglick
Copy link
Contributor

That page 404's for me.

@timroes
Copy link
Collaborator

timroes commented Sep 1, 2022

The page works fine for me.

@krishnaglick
Copy link
Contributor

Could I be missing some permissions?

@timroes
Copy link
Collaborator

timroes commented Sep 1, 2022

@krishnaglick should work now as well for you

@timroes
Copy link
Collaborator

timroes commented Sep 1, 2022

Adding a note here: we often saw a lot of vulnerable dependencies coming from Storybook being really slow in updating their dependencies. Since storybook is not part of our product, it's fine just adding the vulnerable dependencies ,that are only pulled in for storybook to #10573 and close of the relevant dependabot alert as "Risk is tolerable to this project"

@edmundito
Copy link
Contributor Author

Updated the description with the list of PRs currently open instead of the list that some of us can see.

@krishnaglick
Copy link
Contributor

Is the goal to branch off of master and make these changes ourselves so CI runs?

@teallarson teallarson self-assigned this Sep 9, 2022
@teallarson
Copy link
Contributor

Skipped 1/added to the Storybook Issue linked at the top. All others done ✅

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/frontend Related to the Airbyte webapp
Projects
None yet
Development

No branches or pull requests

5 participants