Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependencies in website/: ejs, tough-cookie #36559

Open
wants to merge 3 commits into
base: main
Choose a base branch
from

Conversation

SarahFrench
Copy link
Member

@SarahFrench SarahFrench commented Feb 21, 2025

This PR updates:

  • ejs, 3.1.9 => 3.1.10, which contains the fix "Basic pollution protection" and some docs changes
  • tough-cookie, 4.1.2 => 4.1.4, which contains the fix "Prevent prototype pollution in cookie memstore" and some other fixes that look ok

npm audit before:

49 vulnerabilities (36 moderate, 12 high, 1 critical)

npm audit after:

47 vulnerabilities (34 moderate, 12 high, 1 critical)

Given that these updates are just patches I don't believe that review from Web Presence is necessary (but welcome!)

Target Release

N/A

CHANGELOG entry

  • This change is user-facing and I added a changelog entry.
  • This change is not user-facing.

@SarahFrench SarahFrench added the no-changelog-needed Add this to your PR if the change does not require a changelog entry label Feb 21, 2025
@SarahFrench SarahFrench changed the title Do more simple(r) dependency updates in website/ Update dependencies in website/: ejs, tough-cookie Feb 21, 2025
3.1.9 => 3.1.10
4.1.2 => 4.1.4
@SarahFrench SarahFrench force-pushed the sarah/update-web-dependencies-2 branch from f1dbaf8 to 34ed5d3 Compare February 21, 2025 13:46
@SarahFrench SarahFrench marked this pull request as ready for review February 21, 2025 13:51
@SarahFrench SarahFrench requested review from a team as code owners February 21, 2025 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
no-changelog-needed Add this to your PR if the change does not require a changelog entry
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant