FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Update runner building dependencies by edoardopirovano · Pull Request #663 · github/codeql-action · GitHub

Update runner building dependencies - #663

Merged
edoardopirovano merged 1 commit into
github:mainfrom
edoardopirovano:update-runner-deps
Jul 29, 2021
Merged

edoardopirovano merged 1 commit into
github:mainfrom
edoardopirovano:update-runner-deps

Conversation

Copy link
Copy Markdown
Contributor

The dependencies we use when building the runner can't be automatically updated by Dependabot since they are in a package.json in a sub-folder rather than in the main one. Nonetheless, we should still occasionally update them. In particular, there is currently an alert on one of the transitive dependencies being affected by this CVE (GHSA-ww39-953v-wcq6), which I believe will be resolved by this update.

edoardopirovano requested a review from a team as a code owner July 29, 2021 10:09

adityasharad left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Can we teach Dependabot to look in the subfolder?

Copy link
Copy Markdown
Contributor Author

Can we teach Dependabot to look in the subfolder?

I'll look into it after this PR!

edoardopirovano merged commit 833be9c into github:main Jul 29, 2021
edoardopirovano deleted the update-runner-deps branch July 29, 2021 15:15
github-actions Bot mentioned this pull request Aug 2, 2021
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL