-
Notifications
You must be signed in to change notification settings - Fork 885
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CVE-2021-23382] Bump postcss from 8.2.10 to 8.4.24 #4403
Conversation
Signed-off-by: Zilong Xia <zilongx@amazon.com>
Signed-off-by: Zilong Xia <zilongx@amazon.com>
@ZilongX thank you so much for helping on this. seems #3739 fail to backport to 1.3. I think what you did here is absolutely right. we don't have to update package.json |
Codecov Report
@@ Coverage Diff @@
## 1.3 #4403 +/- ##
==========================================
- Coverage 67.50% 67.46% -0.05%
==========================================
Files 3044 3044
Lines 58692 58692
Branches 8902 8902
==========================================
- Hits 39619 39595 -24
- Misses 16925 16945 +20
- Partials 2148 2152 +4
Flags with carried forward coverage won't be shown. Click here to find out more. |
Thanks @ananzh , just wondering are we still leveraging 1.x branch for any release purposes ? Given we're only release new patch based on 1.3 branch |
Signed-off-by: Zilong Xia <zilongx@amazon.com>
@ananzh updated |
Description
1.3.12
postcss
so just did a lock file refresh to pick up the patch.Issues Resolved
#1094
Check List
yarn test:jest
yarn test:jest_integration
yarn test:ftr