Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update SDR cloud app dependencies #506

Open
t-fine opened this issue Jan 31, 2022 · 2 comments
Open

Update SDR cloud app dependencies #506

t-fine opened this issue Jan 31, 2022 · 2 comments

Comments

@t-fine
Copy link
Collaborator

t-fine commented Jan 31, 2022

There are currently 17 moderate and high severity security vulnerabilities related to the sdr cloud app code. It has gotten to a point npm update can not resolve the dependency tree automatically and will need some more involved and manual fixes as some of the updates will likely involve breaking changes.

@clementkng
Copy link
Contributor

@t-fine so I see two somewhat conflicting bits of work here. One is to just make sure we don't have security vulnerabilities in our code, and the other is to update cloud/sdr as a whole so we can verify that the security fixes we're introducing aren't breaking the code. Given that the security updates have taken priority in the past, I'm going to spin off a new issue to get cloud/sdr working again independently of the security updates. Then, we don't have to care about those manual fixes as much until we're at a place where cloud/sdr is working again.

@t-fine
Copy link
Collaborator Author

t-fine commented Mar 15, 2022

Look up "latest" npm version and go from there

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants