Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release v11 #1162

Merged
merged 2 commits into from
Nov 12, 2021
Merged

Release v11 #1162

merged 2 commits into from
Nov 12, 2021

Conversation

joelanman
Copy link
Contributor

@joelanman joelanman commented Nov 12, 2021

11.0.0 (Fix release)

Fixes

We’ve recently experienced 2 security incidents involving common NPM packages used by the Prototype Kit. We’re sorry for the inconvenience this has caused.

We’ve added new measures (a package-lock.json file) to help prevent this in the future.

To protect your service from any similar threats in future, please upgrade to this new version of the Kit.

Install the Prototype Kit

For any existing prototypes, follow the guide to update the kit.

Pull requests

Pull request #1143: Add a package-lock.json file.

@govuk-design-system-ci govuk-design-system-ci temporarily deployed to govuk-prototype-kit-pr-1162 November 12, 2021 12:54 Inactive
@govuk-design-system-ci govuk-design-system-ci temporarily deployed to govuk-prototype-kit-pr-1162 November 12, 2021 13:26 Inactive
@joelanman joelanman marked this pull request as ready for review November 12, 2021 13:27
@joelanman joelanman merged commit 579c8fb into main Nov 12, 2021
@joelanman joelanman deleted the release-v11 branch November 12, 2021 13:28
@domoscargin domoscargin linked an issue Nov 15, 2021 that may be closed by this pull request
5 tasks
fofr added a commit to x-govuk/govuk-design-history-template that referenced this pull request Dec 10, 2021
Use package-lock to mitigate any issues with dependencies, in the same way the govuk-prototype-kit has done:

alphagov/govuk-prototype-kit#1162
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Create release notes for package lock-related release of GOV.UK Prototype Kit
3 participants