Bug #16052

update serialize-javascript and js-yaml packages

Added by Peter Amstutz almost 2 years ago. Updated over 1 year ago.

Status:
Resolved
Priority:
Normal
Assigned To:
Category:
Workbench2
Target version:
Start date:
01/24/2020
Due date:
% Done:

100%

Estimated time:
(Total: 0.00 h)
Story points:
-


Subtasks

Task #16084: Review 16052-update-packagesResolvedPeter Amstutz

Associated revisions

Revision 20844fff
Added by Lucas Di Pentima over 1 year ago

Merge branch '16052-update-packages'

Closes #16052

Arvados-DCO-1.1-Signed-off-by: Lucas Di Pentima <>

History

#1 Updated by Peter Amstutz almost 2 years ago

  • Description updated (diff)

#2 Updated by Lucas Di Pentima over 1 year ago

  • Status changed from New to In Progress

#3 Updated by Lucas Di Pentima over 1 year ago

Updates at commit 84ef70b - branch 16052-update-packages

By using yarn audit I was able to understand better how the different modules are requested. There're indirect dependencies that require special treatment via a resolutions key on package.json file. See: https://yarnpkg.com/lang/en/docs/selective-version-resolutions/

#4 Updated by Peter Amstutz over 1 year ago

Lucas Di Pentima wrote:

Updates at commit 84ef70b - branch 16052-update-packages

By using yarn audit I was able to understand better how the different modules are requested. There're indirect dependencies that require special treatment via a resolutions key on package.json file. See: https://yarnpkg.com/lang/en/docs/selective-version-resolutions/

This LGTM.

Would it make sense to add yarn audit to our build pipeline somewhere?

#5 Updated by Lucas Di Pentima over 1 year ago

Peter Amstutz wrote:

Would it make sense to add yarn audit to our build pipeline somewhere?

Maybe we can add it as part of the test pipeline. For example checking its errorlevel is >= 8 would fail when issues with priority high or worse are detected: https://legacy.yarnpkg.com/lang/en/docs/cli/audit/#toc-yarn-audit

#6 Updated by Anonymous over 1 year ago

  • Status changed from In Progress to Resolved

Also available in: Atom PDF