Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

fix: upgrade dompurify from 2.2.2 to 2.2.6#1483

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
sy-records merged 1 commit intodocsifyjs:developfromsy-records:dompurify
Feb 4, 2021

Conversation

@sy-records
Copy link
Member

Replace#1470

@vercel
Copy link

vercelbot commentedJan 29, 2021
edited
Loading

This pull request is being automatically deployed with Vercel (learn more).
To see the status of your deployment, click below or on the icon next to each commit.

🔍 Inspect:https://vercel.com/docsify-core/docsify-preview/l6tfu5hbe
✅ Preview:https://docsify-preview-git-fork-sy-records-dompurify.docsify-core.now.sh

@codesandbox-ci
Copy link

This pull request is automatically built and testable inCodeSandbox.

To see build info of the built libraries, clickhere or the icon next to each commit SHA.

Latest deployment of this branch, based on commited7fa16:

SandboxSource
docsify-templateConfiguration

Copy link
Member

@Koooooo-7Koooooo-7 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

it seems there has thesecurity/snyk issue on CI.
@anikethsaha could u plz check and fix it intead of manual upgrade?

@anikethsaha
Copy link
Member

Not sure whether I get this correctly but you are asking for a PR from snyk ?@Koooooo-7

@Koooooo-7
Copy link
Member

Not sure whether I get this correctly but you are asking for a PR from snyk ?@Koooooo-7

yup, the PR of snyk always deletes the dependencies aboutvue inpackage-lock.json. f.e see#1470 .

@Koooooo-7
Copy link
Member

I guess we need move thevue fromdevDependencies todependencies .

@sy-records
Copy link
MemberAuthor

sy-records commentedJan 29, 2021
edited
Loading

The reason I closed#1470 was because it was out of date, 4 versions behind

@sy-records
Copy link
MemberAuthor

Maybe snyk doesn't recognize this style

https://github.com/docsifyjs/docsify/blob/develop/package.json#L106-L107

@sy-recordssy-records merged commiteee9507 intodocsifyjs:developFeb 4, 2021
@sy-recordssy-records deleted the dompurify branchFebruary 4, 2021 00:30
@jhildenbiddle
Copy link
Member

Maybe snyk doesn't recognize this style

https://github.com/docsifyjs/docsify/blob/develop/package.json#L106-L107

@sy-records -- Let's ping Snyk and let them know that their system appears unable to determine when two versions of the same library are listed as dependencies. Otherwise we're just going to run into this issue over and over again. Sounds like@anikethsaha maintains our account?

@anikethsaha
Copy link
Member

Maybe snyk doesn't recognize this style
https://github.com/docsifyjs/docsify/blob/develop/package.json#L106-L107

@sy-records -- Let's ping Snyk and let them know that their system appears unable to determine when two versions of the same library are listed as dependencies. Otherwise we're just going to run into this issue over and over again. Sounds like@anikethsaha maintains our account?

I think@sy-records does have the access, right ?
if not please tell me how to give access, I tried but it wasnt successfull.

@sy-records
Copy link
MemberAuthor

I private messaged you in discord@anikethsaha

anikethsaha reacted with thumbs up emoji

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@Koooooo-7Koooooo-7Koooooo-7 left review comments

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

4 participants

@sy-records@anikethsaha@Koooooo-7@jhildenbiddle

[8]ページ先頭

©2009-2025 Movatter.jp