Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependency: updating socket dependencies to address vulnerabilities #30349

Open
wants to merge 2 commits into
base: develop
Choose a base branch
from

Conversation

quintinchris
Copy link

@quintinchris quintinchris commented Oct 2, 2024

Additional details

hey all!

my organization has ran into security vulnerability issues because of some of the dependencies of this package

both had minor upgrades that resolve the dependency, so i'm updating those in an effort to remediate the vulnerability.

please let me know if there's anything else i can/should do to help get this through.

thanks!

vulnerabilities:

image

Steps to test

How has the user experience changed?

PR Tasks

@CLAassistant
Copy link

CLAassistant commented Oct 2, 2024

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ jennifer-shehane
❌ Chris Quintin


Chris Quintin seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

@cypress-app-bot
Copy link
Collaborator

@jennifer-shehane
Copy link
Member

@quintinchris Could you sign our CLA? We'll need that to accept contributor PRs. I'll update the lockfile and run the tests to see if anything broke. Thanks for opening.

@jennifer-shehane
Copy link
Member

@quintinchris There are some failures with the upgrade that would need addressing. See the CI logs.

@jennifer-shehane jennifer-shehane changed the title (dependency) updating socket dependencies to address vulnerabilities dependency: updating socket dependencies to address vulnerabilities Oct 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants