start-server-and-test icon indicating copy to clipboard operation
start-server-and-test copied to clipboard

Upgrade wait-on version

Open Rach1507 opened this issue 1 year ago • 6 comments

Thank you for taking time to open a new issue. Please answer a few questions to help us fix it faster. You can delete text that is irrelevant to the issue.

Is this a bug report or a feature request?

If this is a bug report, please provide as much info as possible

  • version - 2.0.6
  • platform -
  • expected behavior
  • actual behavior

If this is a new feature request, please describe it below

Raising issue to Upgrade wait-on version as it is pointing to a very old version which is having dependency on axios version - 1.6.1 which is not OSCP compliant

Rach1507 avatar Sep 09 '24 07:09 Rach1507

Hi , also raised PR for it , if it helps #390

Rach1507 avatar Sep 09 '24 08:09 Rach1507

@Rach1507

  • https://github.com/bahmutov/start-server-and-test/pull/390 is already open to upgrade
  • You should be able to run npm audit fix or similar as a workaround, which will update axios to 1.7.7

MikeMcC399 avatar Sep 09 '24 08:09 MikeMcC399

This issue is obsolete and should be closed. wait-on has already been updated.

https://github.com/bahmutov/start-server-and-test/blob/fe1c25dabbf278c418e709945e478a0343262df5/package.json#L140

MikeMcC399 avatar Nov 10 '24 17:11 MikeMcC399

This is still relevant as current version [email protected] relies on [email protected] relies on [email protected] which is vulnerable (see this post) and wait-on just released 8.0.3 to address the issue (see changelog)

hchauvat-owkin avatar Mar 12 '25 15:03 hchauvat-owkin

https://github.com/bahmutov/start-server-and-test/pull/400 fixes this

hchauvat-owkin avatar Mar 12 '25 15:03 hchauvat-owkin

  • https://github.com/bahmutov/start-server-and-test/pull/400 fixes this

Also the above PR has been merged, and so this issue should be closed.

MikeMcC399 avatar Nov 18 '25 10:11 MikeMcC399