Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merge all dev dependencies on main package.json #744

Merged
merged 4 commits into from
Jan 16, 2025
Merged

Conversation

pplancq
Copy link
Contributor

@pplancq pplancq commented Jan 14, 2025

  • chore(design-system): fix no coverage for look-and-feel react
  • chore(design-system): for volta user update node to last lts version
  • chore(design-system): merge all dev dependencies on main package.json
  • chore(design-system): fix npm audit vulnerabilities (1 low, 3 moderate, 1 high)

…e, 1 high)

Severity - high
 - cross-spawn  7.0.0 - 7.0.4 - Regular Expression Denial of Service (ReDoS) in cross-spawn - GHSA-3xgq-45jj-v275
Severity - moderate
 - nanoid  <3.3.8 - Predictable results in nanoid generation when given non-integer values - GHSA-mwcw-c2x4-8c55
 - path-to-regexp  <0.1.12 - Unpatched `path-to-regexp` ReDoS in 0.1.x - GHSA-rhx6-c78j-4q9w
Severity - low
 - cookie  <0.7.0 - cookie accepts cookie name, path, and domain with out of bounds characters - GHSA-pxg6-pf52-xh8x
Copy link

Quality Gate Failed Quality Gate failed

Failed conditions
50.2% Coverage on New Code (required ≥ 80%)
7.7% Duplication on New Code (required ≤ 3%)
C Reliability Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@pplancq pplancq self-assigned this Jan 14, 2025
@pplancq pplancq added chore Issue link to publishing, etc dependencies Package dependencies update labels Jan 14, 2025
@pplancq pplancq merged commit 0434473 into main Jan 16, 2025
7 of 12 checks passed
@pplancq pplancq deleted the feat/packages branch January 16, 2025 06:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
chore Issue link to publishing, etc dependencies Package dependencies update
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants