Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Filings UI: verify and resolve dependency update PRs #10005

Open
severinbeauvais opened this issue Nov 8, 2021 · 0 comments
Open

Filings UI: verify and resolve dependency update PRs #10005

severinbeauvais opened this issue Nov 8, 2021 · 0 comments

Comments

@severinbeauvais
Copy link
Collaborator

severinbeauvais commented Nov 8, 2021

A Github process called "dependabot" automatically creates a PR to update a package dependency to potentially fix a security vulnerability. Eg,

image.png

Before accepting and merging these PRs, each subject package should be reviewed for potential code impacts (eg, breaking changes), and the project should be rebuilt and tested.

The identified "security vulnerabilities" are of moderate or high severity. A summary page is available at: https://github.com/bcgov/business-filings-ui/security/dependabot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants