Skip to content

Chore(package): Remove gitter-sidecar due to vulnerability#13200

Merged
systimotic merged 1 commit intofreeCodeCamp:stagingfrom
Bouncey:fix/removeGitterSidecar
Feb 11, 2017
Merged

Chore(package): Remove gitter-sidecar due to vulnerability#13200
systimotic merged 1 commit intofreeCodeCamp:stagingfrom
Bouncey:fix/removeGitterSidecar

Conversation

@Bouncey
Copy link
Copy Markdown
Member

@Bouncey Bouncey commented Feb 6, 2017

sync.io is flagging the module gitter-sidecar as the source of a vulnerability due to one of it's dependants.

We do not use this module any more

@BerkeleyTrue BerkeleyTrue added the status: waiting review To be applied to PR's that are ready for QA, especially when additional review is pending. label Feb 6, 2017
@raisedadead
Copy link
Copy Markdown
Member

@Bouncey Does this need updates to the .snyk file? I am not aware how this works.

@ghost ghost changed the title Chore(package): Remove gltter-sidecar due to vulnerability Chore(package): Remove gitter-sidecar due to vulnerability Feb 8, 2017
@ghost
Copy link
Copy Markdown

ghost commented Feb 8, 2017

@Bouncey, try running npm run snyk-protect? If it updates the .snyk file, then push the changes to this PRs branch 💪

@Bouncey
Copy link
Copy Markdown
Member Author

Bouncey commented Feb 9, 2017

The .snyk file I think is auto generated and tracks patched applies to modules.

npm run snyk-protect does not change the .synk file.

Copy link
Copy Markdown
Member

@systimotic systimotic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Bouncey I did a check on the Snyk thing. I found out that it should be updated. Running:

snyk wizard
N
n

will yell you no vulnerabilities were found, but it will remove the gitter-sidecar rule from the .snyk file.

@Bouncey
Copy link
Copy Markdown
Member Author

Bouncey commented Feb 11, 2017

Thanks @systimotic, I like learning things!

Copy link
Copy Markdown
Member

@systimotic systimotic left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! 🎉

Thanks for fixing this @Bouncey!

@systimotic systimotic merged commit 02472e1 into freeCodeCamp:staging Feb 11, 2017
@BerkeleyTrue BerkeleyTrue removed the status: waiting review To be applied to PR's that are ready for QA, especially when additional review is pending. label Feb 11, 2017
@teeleek
Copy link
Copy Markdown

teeleek commented Feb 11, 2017 via email

@teeleek
Copy link
Copy Markdown

teeleek commented Feb 11, 2017 via email

@texas2010
Copy link
Copy Markdown
Contributor

@teeleek
looks like you may have accidentally subscribed to all notifications for the FreeCodeCamp repository. To stop receiving notifications please visit the subscriptions page and select "Not watching". Additionally, you can visit the GitHub Help page on managing notification delivery methods for more help.

We are sorry for your inconvenience!

@teeleek
Copy link
Copy Markdown

teeleek commented Feb 12, 2017 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants