Skip to content

Conversation

rBangay
Copy link
Contributor

@rBangay rBangay commented Nov 27, 2024

What does this PR change?

Update peer dependency @guardian/cdk and use the package.json resolutions to force a patched version of cross-spawn

Should fix vulnerability reported by dependabot and snyk:

https://github.com/guardian/manage-frontend/security/dependabot/164
https://app.snyk.io/org/guardian-value/project/8acda083-6b55-431d-a2e0-a985b2349e78

…ncies and forcing a patched version by using the reolutions block in package.json
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant