-
-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Switch to audit resolver to ignore requirejs vulnerability #5573
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
The latest updates on your projects. Learn more about Vercel for Git ↗︎
|
Thank you for your contribution! ❤️You can try out this pull request locally by installing Rollup via npm install rollup/rollup#resolve-audit Notice: Ensure you have installed the latest stable Rust toolchain. If you haven't installed it yet, please see https://www.rust-lang.org/tools/install to learn how to download Rustup and install Rust. or load it into the REPL: |
Performance report!Rough benchmark
Internal benchmark
|
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #5573 +/- ##
=======================================
Coverage 99.04% 99.04%
=======================================
Files 238 238
Lines 9256 9256
Branches 2441 2441
=======================================
Hits 9168 9168
Misses 58 58
Partials 30 30 ☔ View full report in Codecov by Sentry. |
This PR has been released as part of rollup@4.19.0. You can test it via |
This PR contains:
Are tests included?
Breaking Changes?
List any relevant issue numbers:
Description
requirejs
now has an "unfixable" vulnerabilitynpm audit
can not ignore single dependencies but only e.g. alldevDependencies
devDependencies
as some are bundled into rolluprequirejs
is only used in tests where the vulnerability does not matter, and we definitely DO want to keep testing it as it is the standard AMD runtimeTherefore, I am switching from
npm audit
toaudit-resolver
which does allow to ignore single dependencies. To handle audit vulnerabilities, you should now runnpm run resolve-audit
.