Conversation
1 similar comment
| "md5.js": "1.3.4", | ||
| "readable-stream": "~2.0.0", | ||
| "request": "^2.86.0", | ||
| "underscore": "~1.8.3", |
There was a problem hiding this comment.
@XiaoningLiu Do you recall any reason why ~ was used here instead of ^
Am wondering if us making this change will cause any issues
There was a problem hiding this comment.
@ramya-rao-a , @XiaoningLiu , could we run some integration tests in order to validate this security fix?
goelankit
left a comment
There was a problem hiding this comment.
Please update the package version as well. We are looking to consume this change downstream as we are getting security alerts as well for this dependency.
|
@XiaoningLiu without a package update this merge isn't helping anyone. |
|
@HarshaNalluru Let's release this. |
|
Hi, Thanks |
|
@EmmaZhu @XiaoningLiu Can we help in any way to speed up the release? |
Component Governance from DevOps complains of the underscore dependency in azure-sdk-for-js repo.