-
Notifications
You must be signed in to change notification settings - Fork 90
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): upgrade polished dep due to security vulnerability #1127
fix(deps): upgrade polished dep due to security vulnerability #1127
Conversation
Looks good. What was the steps (commands) to make this upgrade? I want to verify it locally on my machine. |
@hzhu, unfortunately, |
@hzhu actually might have to decline this PR as it looks like I might have to update |
It looks like polished isn't a shared dependency at the root mono repo level, and the dependency found in the root There are sub-packages that use polished, and those may be the packages that you're looking to upgrade? E.g. |
@hzhu the issue looks to be |
Looks like Since polished isn't a cross-package dependency (e.g not defined at the top-level |
@JamesSingleton any updates on this one? |
https://app.snyk.io/vuln/npm:polished
Description
Upgrades the
polished
dependency to address https://app.snyk.io/vuln/npm:polishedDetail
Checklist
designer as a reviewer)
yarn start
)?bedrock
)