Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update several packages to address vulnerability warnings #2863

Merged
merged 3 commits into from
Jul 19, 2018

Conversation

jsnellbaker
Copy link
Collaborator

@jsnellbaker jsnellbaker commented Jul 18, 2018

Type of change

  • Build related changes

Description of change

Update the coveralls, gulp-connect, nightwatch packages and remove the gulp-webdriver package as it isn't needed.

The update to coveralls is to partially address an issue with a devDependency package chain that uses vulnerable version of hoek. Details on the vulnerability can be found here. These newer packages use a different chain that doesn't install hoek.

The updates to gulp-connect and nightwatch were to address other vulnerability warnings that were seen when running npm install. Details of the warnings can be seen with npm audit.

Note
The latest version of Karma (2.0.4) we use still has a dependency chain that uses the vulnerable version of hoek, so there's nothing to be done to fully address the issue at this time.

@jaiminpanchal27
Copy link
Collaborator

I think we are not using gulp-webdriver anywhere. Someone might i have installed to try out http://webdriver.io/ test runner.

@jsnellbaker
Copy link
Collaborator Author

Thanks for the heads-up. I pushed a commit to remove these packages from the files.

@jsnellbaker jsnellbaker changed the title update coveralls and webdriver pacakges update several packages to address vulnerability warnings Jul 18, 2018
@jsnellbaker jsnellbaker added needs 2nd review Core module updates require two approvals from the core team and removed in progress labels Jul 18, 2018
@jaiminpanchal27 jaiminpanchal27 merged commit 54ba1d2 into master Jul 19, 2018
@mkendall07 mkendall07 deleted the update_hoek branch August 17, 2018 15:12
florevallatmrf pushed a commit to Marfeel/Prebid.js that referenced this pull request Sep 6, 2018
* update coveralls and webdriver pacakges

* remove gulp-webdriver and webdriverio packages

* update additional packages to fix other vulnerabilities
StefanWallin pushed a commit to mittmedia/Prebid.js that referenced this pull request Sep 28, 2018
* update coveralls and webdriver pacakges

* remove gulp-webdriver and webdriverio packages

* update additional packages to fix other vulnerabilities
ghost pushed a commit to devunrulymedia/Prebid.js that referenced this pull request Jan 30, 2019
* update coveralls and webdriver pacakges

* remove gulp-webdriver and webdriverio packages

* update additional packages to fix other vulnerabilities
AlessandroDG pushed a commit to simplaex/Prebid.js that referenced this pull request Mar 26, 2019
* update coveralls and webdriver pacakges

* remove gulp-webdriver and webdriverio packages

* update additional packages to fix other vulnerabilities
AlessandroDG pushed a commit to simplaex/Prebid.js that referenced this pull request Mar 26, 2019
* update coveralls and webdriver pacakges

* remove gulp-webdriver and webdriverio packages

* update additional packages to fix other vulnerabilities
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs 2nd review Core module updates require two approvals from the core team
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants