Skip to content

STOP-1012(Bump): semver version updated for security issues#262

Merged
SB-rohitdesai merged 2 commits intomasterfrom
security/ticket-1012
Sep 26, 2024
Merged

STOP-1012(Bump): semver version updated for security issues#262
SB-rohitdesai merged 2 commits intomasterfrom
security/ticket-1012

Conversation

@SB-rohitdesai
Copy link
Copy Markdown
Contributor

@SB-rohitdesai SB-rohitdesai commented Sep 20, 2024

Motivation and Context

#STOP-1012

Description

A vulnerability was detected within the json-schema-viewer project through the inclusion of the semver dependency.
Semver is internally used by @size-limit/preset-big-lib this package. to resolve this dependency we updated @size-limit/preset-big-lib package.

How Has This Been Tested?

  1. Locally tested , test cases , build and code also running and working properly
  2. Yalc the change into platform-internal and tested

Screenshot(s)/recordings(s)

image image image

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)

Checklist

@bhaskarsontakke
Copy link
Copy Markdown

@SB-rohitdesai please yalc the json-schema-viewer and test in platform-internal. Make sure you cover all the places where JSON-SCHEMA-VIEWER is used. Also, run the all the test cases.

@SB-rohitdesai
Copy link
Copy Markdown
Contributor Author

@SB-rohitdesai please yalc the json-schema-viewer and test in platform-internal. Make sure you cover all the places where JSON-SCHEMA-VIEWER is used. Also, run the all the test cases.

Done

@SB-rohitdesai SB-rohitdesai changed the title bump: version updated for security issues STOP-1012(fix): version updated for security issues Sep 25, 2024
@SB-rohitdesai SB-rohitdesai changed the title STOP-1012(fix): version updated for security issues STOP-1012(bump): version updated for security issues Sep 25, 2024
@SB-rohitdesai SB-rohitdesai changed the title STOP-1012(bump): version updated for security issues STOP-1012(bump): semver version updated for security issues Sep 25, 2024
Copy link
Copy Markdown

@bhaskarsontakke bhaskarsontakke left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As it's dev dependencies, and it's working on CI commit to calculate the cost of your JS. If I understand correctly, I do not see any functional impact.

@SB-rohitdesai SB-rohitdesai changed the title STOP-1012(bump): semver version updated for security issues bump: semver version updated for security issues Sep 25, 2024
@SB-rohitdesai SB-rohitdesai changed the title bump: semver version updated for security issues STOP-1012(Bump): semver version updated for security issues Sep 25, 2024
Copy link
Copy Markdown

@prafullaAtSB prafullaAtSB left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good on devDependences front.
Go ahead. Check with other products using yalc

@SB-rohitdesai
Copy link
Copy Markdown
Contributor Author

Looks good on devDependences front. Go ahead. Check with other products using yalc

Yes , checked with other repo's

@SB-rohitdesai SB-rohitdesai merged commit 9fc73fe into master Sep 26, 2024
@SB-rohitdesai SB-rohitdesai deleted the security/ticket-1012 branch September 26, 2024 06:56
@stoplight-bot
Copy link
Copy Markdown
Collaborator

🎉 This PR is included in version 4.16.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants