jest-preview icon indicating copy to clipboard operation
jest-preview copied to clipboard

Having dependabot alerts: Got allows a redirect to a UNIX socket

Open KieraDOG opened this issue 2 years ago • 2 comments

Describe the bug

Hi team, we are having this dependabot alert of dependency from jest-preview.

The latest possible version that can be installed is 9.6.0 because of the following conflicting dependency:

[email protected] requires got@^9.6.0 via a transitive dependency on [email protected]

The earliest fixed version is 11.8.5.

Screenshots

Reproduce

Please provide a minimal reproduction for the issue. Thanks.

You can use one of the following options to reproduce the issue:

  • Create a new GitHub repository (recommended): https://github.com/new
  • Create a StackBlitz project: https://stackblitz.com
  • Create a sandbox on CodeSandbox: https://codesandbox.io/s

Expected behavior

Upgrade update-notifier to latest version should be able to solve this problem

Environment (please complete the following information)

  • OS: [e.g. macOS 12.2.1, Windows 11, Ubuntu 22.04]
  • Browser: [e.g. chrome, safari]
  • Jest version: [e.g. 27.5.1]

Additional context

KieraDOG avatar Oct 25 '22 01:10 KieraDOG

Unluckily, update-notifier@6 does not play well with jest-preview's bundling logic. I will workaround by downgrading update-notifier 6 => 5. I hope I can find a better solution in the future

nvh95 avatar Jan 01 '23 16:01 nvh95

Any progress on a fix for this?

snout-o avatar Jan 09 '24 06:01 snout-o