Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Update NPM devDependencies #3651

Merged
merged 1 commit into from
Mar 25, 2024
Merged

chore: Update NPM devDependencies #3651

merged 1 commit into from
Mar 25, 2024

Conversation

tobybellwood
Copy link
Member

@tobybellwood tobybellwood commented Feb 9, 2024

This PR updates a heap of the NPM dependencies in Lagoon. This should help us to target efforts better at the core packages in use.

It also reduces the number of vulnerabilities in the images

## Overview
  
                      │           Analyzed Image           │              Comparison Image               
  ────────────────────┼────────────────────────────────────┼─────────────────────────────────────────────
    Target            │  lagoon/api:latest                 │  uselagoon/api:latest                       
      digest          │  02c172452e33                      │  6a7f1a82e9db                               
      platform        │ linux/amd64                        │ linux/amd64                                 
      provenance      │                                    │ https://github.com/uselagoon/lagoon.git     
                      │                                    │  18b3b827c73f740d61a9c1900926a87c1adaaa4a   
      vulnerabilities │    1C    17H    41M     3L     1?  │   10C    31H    62M     3L     2?           
                      │    -9    -14    -21            -1  │                                             
      size            │ 146 MB (-30 MB)                    │ 176 MB                                      
      packages        │ 1316 (-333)                        │ 1649                                        
                      │                                    │                                             
    Base image        │  node:20-alpine                    │  node:20-alpine                             
      tags            │ also known as                      │ also known as                               
                      │   • 20-alpine3.19                  │   • 20-alpine3.18                           
                      │   • 20.11-alpine                   │   • iron-alpine                             
                      │   • 20.11-alpine3.19               │   • iron-alpine3.18                         
                      │   • 20.11.0-alpine                 │   • lts-alpine                              
                      │   • 20.11.0-alpine3.19             │   • lts-alpine3.18                          
                      │   • iron-alpine                    │                                             
                      │   • iron-alpine3.19                │                                             
                      │   • lts-alpine                     │                                             
                      │   • lts-alpine3.19                 │                                             
      vulnerabilities │    0C     0H     2M     0L     1?  │    0C     0H     2M     0L     1?           
  
  

@tobybellwood tobybellwood force-pushed the testing/npm-updates branch from aad4b34 to 7028127 Compare March 5, 2024 01:49
@tobybellwood tobybellwood marked this pull request as ready for review March 7, 2024 01:53
@tobybellwood tobybellwood force-pushed the testing/npm-updates branch 2 times, most recently from 0a98af1 to a6c07dd Compare March 13, 2024 01:54
@tobybellwood tobybellwood added this to the 2.18.0 milestone Mar 13, 2024
@tobybellwood tobybellwood merged commit a2366bf into main Mar 25, 2024
1 check passed
@tobybellwood tobybellwood deleted the testing/npm-updates branch July 4, 2024 22:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant