Logan/eng 469 fix tinacms dependency vulnerabilities#3088
Conversation
ENG-469 Fix tinacms dependency vulnerabilities
A user in Discord pointed out we have some dependency vulnerabilities: https://github.com/tinacms/tinacms/security/dependabot?page=1&q=is%3Aopen |
🦋 Changeset detectedLatest commit: a14bdc4 The changes in this PR will be included in the next version bump. This PR includes changesets to release 13 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Modified PackagesThe following packages were modified by this pull request:
|
We should probably make sure we understand why that's happening. Might be related node-fetch/node-fetch#675. |
@jeffsee55 I think that is the issue |
|
Some key things to review for the PR
|
|
@logan-anderson there are some conflicts with main - you want to resolve before we validate this? |
@kldavis4 I have update it. Good catch |
|
when I run It looks like the build succeeds, so not sure if this is an issue. In the main branch, it fails completely |
|
…bilities the commit.
Co-authored-by: Jeff See <jeffsee.55@gmail.com>
Co-authored-by: Jeff See <jeffsee.55@gmail.com>
Co-authored-by: Jeff See <jeffsee.55@gmail.com>
Co-authored-by: Jeff See <jeffsee.55@gmail.com>
kldavis4
left a comment
There was a problem hiding this comment.
Everything in the validation list is now working for me.
@jamespohalloran do we need to make corresponding changes in the standalone tina-cloud-starter repo?
Yep I think all our starters will have to upgrade next, and tinacms once this is out |
Updates deps to remove vulnerabilities.
One known issue.
When updating next I get this warning
It does not seem to effect anything.