Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps/devDeps: bump semver to latest [CVE-2022-25883] #349

Merged
merged 1 commit into from
Oct 8, 2023

Conversation

legobeat
Copy link
Contributor

@legobeat legobeat commented Sep 3, 2023

Removes dependencies on broken:

  • semver@5.7.1
  • semver@7.3.8
  • semver@6.3.0

Fixes:

Version

Published prerelease version: v0.13.1-next.1

Changelog

🐛 Bug Fix

🏠 Internal

Authors: 3

@legobeat legobeat marked this pull request as ready for review September 3, 2023 00:56
@legobeat
Copy link
Contributor Author

legobeat commented Sep 4, 2023

@yannbf PTAL

@legobeat
Copy link
Contributor Author

legobeat commented Sep 6, 2023

After rebase on next after recent merges, there is one entry for semver@^5 being resolved in this PR, besides the range of the direct dependency in package.json.

@codecov
Copy link

codecov bot commented Sep 6, 2023

Codecov Report

All modified lines are covered by tests ✅

Comparison is base (5dd0322) 76.66% compared to head (2f4c381) 76.66%.

Additional details and impacted files
@@           Coverage Diff           @@
##             next     #349   +/-   ##
=======================================
  Coverage   76.66%   76.66%           
=======================================
  Files          11       11           
  Lines         180      180           
  Branches       40       40           
=======================================
  Hits          138      138           
  Misses         42       42           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@yannbf yannbf added the patch Increment the patch version when merged label Oct 8, 2023
Copy link
Member

@yannbf yannbf left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is great, thank you so much for your contribution!

@yannbf yannbf merged commit 5740667 into storybookjs:next Oct 8, 2023
9 checks passed
@legobeat legobeat deleted the deps-semver branch October 9, 2023 23:45
@legobeat legobeat restored the deps-semver branch October 9, 2023 23:45
@yannbf yannbf mentioned this pull request Nov 8, 2023
Copy link

github-actions bot commented Nov 8, 2023

🚀 PR was released in v0.14.0 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
patch Increment the patch version when merged released
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants