Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: replace vulnerable dependencies for uploadcare #2476

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

t-col
Copy link
Contributor

@t-col t-col commented Aug 6, 2024

Removes dependency on unmaintained react-scripts package, replaces it with vite/vitest

@t-col t-col changed the title chore: deprecate vulnerable dependencies for uploadcare chore: replace vulnerable dependencies for uploadcare Aug 7, 2024
@t-col t-col force-pushed the chore/deprecate-vulnerable-deps-uploadcare branch from f471582 to 4150d9e Compare August 7, 2024 23:00
@t-col t-col force-pushed the chore/deprecate-vulnerable-deps-uploadcare branch from 4150d9e to 63f7056 Compare August 12, 2024 21:49
@t-col t-col marked this pull request as ready for review August 12, 2024 21:49
@t-col t-col requested a review from a team as a code owner August 12, 2024 21:49
@t-col
Copy link
Contributor Author

t-col commented Aug 12, 2024

Hello @igoradamenko -- this Pull Request is being directed to you as a Contentful Marketplace App owner

This PR removes your apps dependence on react-scripts in favor of vite (and vitest). This is done in service of removing security vulnerabilities. You may see other nested dependencies updated as well, like typescript or emotion/css, as these libraries were required for react-scripts and often pinned to stale or deprecated versions. While the PR is complete, we’d like your help as the owner of the app, to confirm that no bugs or regressions have been introduced with these updates.

Required Action:

Please review this PR, and QA your app with these changes. If all functionality remains safely intact, please just reply with a "LGTM" (or more) and we’ll merge the PR and release these changes.

If you do discover issues as a result of these changes, please open a new PR against this branch with fixes once identified.

Please plan to complete this action within 30 days.

Sincerely,
The Contentful Ecosystem Team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant