Skip to content

Commit ac643a4

Browse files
committed
fix: Ignore vulnerability that cannot be upgraded
Additionally, this vulnerability should not be able to touch the package using it (@vue/cli-plugin-unit-jest) See vuejs/vue-cli#5573 for more
1 parent c6f9684 commit ac643a4

File tree

5 files changed

+13
-2
lines changed

5 files changed

+13
-2
lines changed

.gitlab-ci.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,9 @@ JavaScript vulnerabilities:
6565
stage: check dependencies
6666
script:
6767
- 'eval $MAKE check-node-dependencies-for-vulnerabilities'
68-
needs: []
68+
needs:
69+
- job: initialize
70+
artifacts: true
6971

7072
outdated (Python) dependencies:
7173
stage: check dependencies

Makefile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -459,7 +459,7 @@ safety-check:
459459
$(PIPENV) check
460460

461461
check-node-dependencies-for-vulnerabilities:
462-
$(YARN) audit
462+
$(YARN) run improved-yarn-audit --fail-on-missing-exclutions
463463

464464
update-dependencies: update-node-dependencies update-python-dependencies
465465

src/gui/.iyarc

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
# 1500 ignored because there is no fix available for it, until @vue/cli-plugin-unit-jest version 5.x
2+
3+
1500

src/gui/package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,7 @@
7979
"fibers": "^4.0.2",
8080
"file-loader": "^5.0.2",
8181
"ify-loader": "^1.1.0",
82+
"improved-yarn-audit": "^2.3.1",
8283
"jest": "^24.5.0",
8384
"jest-webpack-resolver": "^0.3.0",
8485
"lint-staged": "^9.2.0",

src/gui/yarn.lock

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7417,6 +7417,11 @@ import-local@^2.0.0:
74177417
pkg-dir "^3.0.0"
74187418
resolve-cwd "^2.0.0"
74197419

7420+
improved-yarn-audit@^2.3.1:
7421+
version "2.3.1"
7422+
resolved "https://registry.yarnpkg.com/improved-yarn-audit/-/improved-yarn-audit-2.3.1.tgz#e937f32e4da250eece077693c612caef05be435b"
7423+
integrity sha512-jMME3sGF8RosTpQ7CMoel4F8UKJs6bvP2Dc11gkZrKynxBpulQ4bJKgGydnAyHgDavJw6NbssMrbqwVSiuw5Ug==
7424+
74207425
imurmurhash@^0.1.4:
74217426
version "0.1.4"
74227427
resolved "https://registry.yarnpkg.com/imurmurhash/-/imurmurhash-0.1.4.tgz#9218b9b2b928a238b13dc4fb6b6d576f231453ea"

0 commit comments

Comments
 (0)