Uploaded image for project: 'mod-graphql'
  1. mod-graphql
  2. MODGQL-138

Dependency updates: json-ptr, underscore, xmldom; yarn.lock

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • TBD
    • Resolution: Done
    • 1.8.0
    • 1.9.0
    • Thor

    Description

      raml-1-parser has these vulnerable dependencies:

      raml-1-parser is no longer maintained: https://www.npmjs.com/package/raml-1-parser

      Task:

      Use "resolutions" section in package.json to bump the dependencies to fixed versions.

      In addition "yarn upgrade" yarn.lock. This enforces fixed versions and also signals GitHub's dependabot that mod-graphql no longer has potential security issues.

      TestRail: Results

        Attachments

          Issue Links

            Activity

              People

                mike Mike Taylor
                julianladisch Julian Ladisch
                Votes:
                0 Vote for this issue
                Watchers:
                2 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:

                  TestRail: Runs

                    TestRail: Cases