Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

search-ui-react: Resolve Vulnerabilities #484

Open
wants to merge 4 commits into
base: main
Choose a base branch
from
Open

Conversation

mkouzel-yext
Copy link
Contributor

Upgrades dependency versions to resolve potential vulnerabilities.

Regenerates package-lock.json to include the safe dependencies.

J=VULN-39418, VULN-39419
TEST=none

Saw that babel imports in package-lock.json and test-site/package-lock.json
were for versions at or above the safe dependency.
@mkouzel-yext mkouzel-yext requested a review from a team as a code owner January 29, 2025 22:15
@semgrep-code-yext
Copy link

Legal Risk

The following dependencies were released under a license that
is currently prohibited by your organization. Merging is blocked until this is resolved.

Recommendation

Reach out to your security team or Semgrep admin to address this issue. In special cases, exceptions may be made for dependencies with violating licenses, however, the general recommendation is to avoid using a dependency under such a license

non-standard

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant