fix: upgrade vulnerable dependencies - #108
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (5)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
📄 Knowledge reviewDosu skipped reviewing this PR because your organization has used its |
这个在项目整体依赖包升级(
这两个包相比之前都是跨多个版本的大版本升级,请确认 API 是否兼容,否则就升级到同一大版本的最新小版本。 |
|
已确认这两个跨主版本升级,结论如下。
修正提交: 验证结果:
|
Closes #109
Summary
pnpm audit --prod.Security impact
postcssto 8.5.25.sharpto 0.35.3.serialize-javascriptto 7.0.7.brace-expansionto 5.0.9.GitHub currently reports four open alerts on the default branch.
These changes address the affected
postcssandsharpversions.Checks
pnpm install --frozen-lockfilepassed.pnpm audit --prodpassed with no known vulnerabilities.pnpm exec tsc --noEmitpassed.pnpm exec eslint .found 62 existing errors in unchanged source files.pnpm run buildcompiled the application successfully./NGOdata service returned HTTP 402.DEPLOYMENT_DISABLED.