Skip to content

Comments

chore(project): raise versions of dependencies in order to address vulnerabilities#228

Merged
KeiKey merged 1 commit intomainfrom
feature/vulnerabilities-remediate
Jun 23, 2025
Merged

chore(project): raise versions of dependencies in order to address vulnerabilities#228
KeiKey merged 1 commit intomainfrom
feature/vulnerabilities-remediate

Conversation

@KeiKey
Copy link
Contributor

@KeiKey KeiKey commented Jun 16, 2025

  1. brace-expansion set to version 1.1.12 in order to address a vulnerability.
  2. The following packages were upgraded to the recommended version
    "rimraf": "5.0.10" -> [Snyk] Upgrade mammoth from 1.7.1 to 1.9.0 #207
    "mammoth": "1.9.0" -> [Snyk] Upgrade rimraf from 5.0.5 to 5.0.10 #206
  3. Playwright wasnt upgraded to the recommended version because of some reported issues I found online. Not worth the risk
  4. @google-cloud/translate set to version 9.1.0 (rather than the recommended version) because of a warning that is in the lower versions.
    image

@gamer496
Copy link
Contributor

@KeiKey for point 3 regarding playwright, could you please share a brief reason and links as to what the risk is and why isn't it worth it?

@dcxn dcxn requested a review from gamer496 June 18, 2025 13:00
@KeiKey
Copy link
Contributor Author

KeiKey commented Jun 20, 2025

@KeiKey for point 3 regarding playwright, could you please share a brief reason and links as to what the risk is and why isn't it worth it?

Before upgrading I checked online and came across some report of performance issues with version 1.50. Can't find it at the moment because not saved. Did a skimming of the reported issues on Github and came across some performance related issues there as well.

Snyk PR was about upgrading to a recommended version, not vulnerability related. Didn't go into details of the issues reported, just skipped it as not worth it.

@KeiKey KeiKey merged commit 532e323 into main Jun 23, 2025
3 checks passed
@dcxn
Copy link
Collaborator

dcxn commented Jul 15, 2025

🎉 This PR is included in version 1.8.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

@dcxn dcxn added the released label Jul 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants