Skip to content

Update dependency to resolve json5 dependabot alert#2645

Merged
edwardlee-msft merged 3 commits intomainfrom
elee/update-json5
Jan 10, 2023
Merged

Update dependency to resolve json5 dependabot alert#2645
edwardlee-msft merged 3 commits intomainfrom
elee/update-json5

Conversation

@edwardlee-msft
Copy link
Copy Markdown
Contributor

@edwardlee-msft edwardlee-msft commented Jan 10, 2023

What

json5 vulnerability detected by dependabot alert.
vulnerability was patched and backported to json5 versions 1 that are >= 1.0.2 and versions >= 2.2.2.
rush update pnpm-lock files to use 1.0.2 json5 versions.

image

Why

https://github.com/Azure/communication-ui-library/security/dependabot/77

How Tested

Process & policy checklist

  • I have updated the project documentation to reflect my changes if necessary.
  • I have read the CONTRIBUTING documentation.

Is this a breaking change?

  • This change causes current functionality to break.

@github-actions
Copy link
Copy Markdown
Contributor

Chat bundle size is increased❗.

  • Current size: 5585480
  • Base size: 5584996
  • Diff size: 484

@github-actions
Copy link
Copy Markdown
Contributor

CallWithChat bundle size is increased❗.

  • Current size: 5880518
  • Base size: 5880036
  • Diff size: 482

@github-actions
Copy link
Copy Markdown
Contributor

Calling bundle size is increased❗.

  • Current size: 5496023
  • Base size: 5496007
  • Diff size: 16

@edwardlee-msft edwardlee-msft merged commit 4ab34a7 into main Jan 10, 2023
@edwardlee-msft edwardlee-msft deleted the elee/update-json5 branch January 10, 2023 21:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants