Skip to content

High Severity Dependabot alerts for @commercetools-frontend/mc-scripts #2953

@nick-loyalty

Description

@nick-loyalty

This issue is relevant to Dependabot alerts, we got two High Severity Alerts from Dependabot as it needs two components update
Screen Shot 2023-02-02 at 12 12 08 pm
Screen Shot 2023-02-02 at 12 12 25 pm

These two components are both relevant to @commercetools-frontend/mc-scripts when we do npm ls
Screen Shot 2023-02-02 at 1 04 23 pm
Screen Shot 2023-02-02 at 1 04 59 pm
As we can see in the above, with the latest @commercetools-frontend/mc-scripts, it is still using minimatch@3.0.4 which Dependabot needs minimatch@3.0.5 and json5@0.5.1 which Dependabot needs json5@1.0.2.

Can we upgrade the @commercetools-frontend/mc-scripts to support newer version minimatch and json5 ?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions