Skip to content
This repository was archived by the owner on Oct 7, 2024. It is now read-only.

Use mocha@8.1.1#55

Merged
whymarrh merged 1 commit intomasterfrom
update-mocha
Aug 13, 2020
Merged

Use mocha@8.1.1#55
whymarrh merged 1 commit intomasterfrom
update-mocha

Conversation

@whymarrh
Copy link
Copy Markdown
Contributor

This PR updates mocha to the latest published version to address a security advisory with its serialize-javascript dependency.

See https://www.npmjs.com/advisories/1548 for more information.

The yarn audit output:

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ high          │ Remote Code Execution                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ serialize-javascript                                         │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=3.1.0                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ mocha                                                        │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ mocha > serialize-javascript                                 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://www.npmjs.com/advisories/1548                        │
└───────────────┴──────────────────────────────────────────────────────────────┘

@whymarrh whymarrh requested a review from a team as a code owner August 13, 2020 15:56
Copy link
Copy Markdown
Member

@Gudahtt Gudahtt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@whymarrh whymarrh merged commit eb1f428 into master Aug 13, 2020
@whymarrh whymarrh deleted the update-mocha branch August 13, 2020 16:06
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants