paragon icon indicating copy to clipboard operation
paragon copied to clipboard

Paragon vulnerablities resolution

Open BilalQamar95 opened this issue 3 years ago • 2 comments

Description

  • Updated gatsby to latest version & packages in package-lock.json to resolve vulnerabilities
  • Updated frontend-build to v12 for example app & subsequent resolved eslint issues
  • Updated packages in package-lock.json to resolve vulnerali

Deploy Preview

Include a direct link to your changes in this PR's deploy preview here (e.g., a specific component page).

Merge Checklist

  • [ ] If your update includes visual changes, have they been reviewed by a designer? Send them a link to the Netlify deploy preview, if applicable.
  • [ ] Does your change adhere to the documented style conventions?
  • [ ] Do any prop types have missing descriptions in the Props API tables in the documentation site (check deploy preview)?
  • [ ] Were your changes tested using all available themes (see theme switcher in the header of the deploy preview, under the "Settings" icon)?
  • [ ] Were your changes tested in the example app?
  • [ ] Is there adequate test coverage for your changes?
  • [ ] Consider whether this change needs to reviewed/QA'ed for accessibility (a11y). If so, please add wittjeff and adamstankiewicz as reviewers on this PR.

Post-merge Checklist

  • [ ] Verify your changes were released to NPM at the expected version.
  • [ ] If you'd like, share your contribution in #show-and-tell.
  • [ ] 🎉 🙌 Celebrate! Thanks for your contribution.

BilalQamar95 avatar Sep 29 '22 06:09 BilalQamar95

Deploy Preview for paragon-openedx ready!

Name Link
Latest commit 891798d72d292295d434839708c2f3ddffba6265
Latest deploy log https://app.netlify.com/sites/paragon-openedx/deploys/646dde25d1215c0008059a19
Deploy Preview https://deploy-preview-1649--paragon-openedx.netlify.app
Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

netlify[bot] avatar Sep 29 '22 06:09 netlify[bot]

Codecov Report

Patch and project coverage have no change.

Comparison is base (2d6c050) 91.38% compared to head (891798d) 91.38%.

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #1649   +/-   ##
=======================================
  Coverage   91.38%   91.38%           
=======================================
  Files         234      234           
  Lines        4120     4120           
  Branches      982      982           
=======================================
  Hits         3765     3765           
  Misses        348      348           
  Partials        7        7           

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Do you have feedback about the report comment? Let us know in this issue.

codecov[bot] avatar Sep 29 '22 06:09 codecov[bot]

@BilalQamar95 When you get a chance, I have a couple requests for this PR:

  • Can we split out the @edx/frontend-build upgrade and subsequent ESLint changes as its own PR? That would leave this PR only for upgrading the Gatsby and package-lock.json modules.
  • Can we get this back up to date with master?

adamstankiewicz avatar Jan 27 '23 21:01 adamstankiewicz

@BilalQamar95 When you get a chance, I have a couple requests for this PR:

  • ~Can we split out the @edx/frontend-build upgrade and subsequent ESLint changes as its own PR?~ That would leave this PR only for upgrading the Gatsby and package-lock.json modules.
  • Can we get this back up to date with master?

Apologies, it looks like @edx/frontend-build is already at v12.3.0 in this repo. The Gatsby ecosystem upgrade is definitely still relevant, though (related PR).

adamstankiewicz avatar Jan 27 '23 22:01 adamstankiewicz

This seems like it's still relevant. @BilalQamar95, do you mind resolving conflicts? @adamstankiewicz, once he does, any objections to merging it?

arbrandes avatar May 23 '23 14:05 arbrandes

:tada: This PR is included in version 20.40.2 :tada:

The release is available on:

Your semantic-release bot :package::rocket:

edx-semantic-release avatar Jun 01 '23 07:06 edx-semantic-release

:tada: This PR is included in version 21.0.0-alpha.31 :tada:

The release is available on:

Your semantic-release bot :package::rocket:

edx-semantic-release avatar Jun 02 '23 07:06 edx-semantic-release