Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Yarn dependencies #3805

Merged
merged 5 commits into from
Sep 15, 2024
Merged

Update Yarn dependencies #3805

merged 5 commits into from
Sep 15, 2024

Conversation

tobybellwood
Copy link
Member

@tobybellwood tobybellwood commented Sep 13, 2024

This PR

  • updates updatable packages
  • updates a few specific low-impact packages
  • Removes unreferenced packages
  • Updates the version of NewRelic Agent in use

Remaining critical is a long way down the chain, and unavailable to external access
api > graphql-rabbitmq-subscriptions > rabbitmq-pub-sub > amqplib > url-parse

From

57 vulnerabilities found - Packages audited: 811
Severity: 3 Low | 36 Moderate | 17 High | 1 Critical
Done in 3.14s

to

24 vulnerabilities found - Packages audited: 825
Severity: 17 Moderate | 6 High | 1 Critical
Done in 1.19s
docker scout compare --to uselagoon/api:v2.20.1 testlagoon/api:pr-3805
## Overview
  
                      │               Analyzed Image               │              Comparison Image               
  ────────────────────┼────────────────────────────────────────────┼─────────────────────────────────────────────
    Target            │  testlagoon/api:pr-3805                    │  uselagoon/api:v2.20.1                      
      digest          │  45336077b139                              │  6d27627c7bc5                               
      tag             │  pr-3805                                   │  v2.20.1                                    
      platform        │ linux/amd64                                │ linux/amd64                                 
      provenance      │ https://github.com/uselagoon/lagoon.git    │ https://github.com/uselagoon/lagoon.git     
                      │  09f24c51b8aebf3295bd1c79e705ea1a814065a9  │  8b8a4ef00a78b1b9fed1dfd970337de445c965a2   
      vulnerabilities │    3C    28H    37M     2L    10?          │    3C    30H    49M     5L     6?           
                      │           -2    -12     -3     +4          │                                             
      size            │ 118 MB (-1.1 MB)                           │ 119 MB                                      
      packages        │ 1309                                       │ 1309                                        
                      │                                            │                                             
    Base image        │  node:20-alpine                            │  node:20-alpine3.19                         
      tags            │ also known as                              │ also known as                               
                      │   • 20-alpine3.20                          │   • iron-alpine3.19                         
                      │   • 20.17-alpine                           │   • lts-alpine3.19                          
                      │   • 20.17-alpine3.20                       │                                             
                      │   • 20.17.0-alpine                         │                                             
                      │   • 20.17.0-alpine3.20                     │                                             
                      │   • iron-alpine                            │                                             
                      │   • iron-alpine3.20                        │                                             
                      │   • lts-alpine                             │                                             
                      │   • lts-alpine3.20                         │                                             
      vulnerabilities │    0C     1H     0M     0L                 │    1C     1H     0M     0L     1? 

@tobybellwood tobybellwood added this to the 2.21.0 milestone Sep 13, 2024
@tobybellwood tobybellwood merged commit 8687dbf into main Sep 15, 2024
2 checks passed
@tobybellwood tobybellwood deleted the testing/yarn_update branch September 16, 2024 23:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant