Uh oh!
There was an error while loading. Please reload this page.
fix: upgrade dompurify from 2.2.2 to 2.2.6 - #1483
Conversation
This pull request is being automatically deployed with Vercel (learn more). 🔍 Inspect: https://vercel.com/docsify-core/docsify-preview/l6tfu5hbe |
This pull request is automatically built and testable in CodeSandbox. To see build info of the built libraries, click here or the icon next to each commit SHA. Latest deployment of this branch, based on commit ed7fa16:
|
Koooooo-7
left a comment
There was a problem hiding this comment.
it seems there has the security/snyk issue on CI.
@anikethsaha could u plz check and fix it intead of manual upgrade?
anikethsaha
commented
Jan 29, 2021
Not sure whether I get this correctly but you are asking for a PR from snyk ? @Koooooo-7 |
Koooooo-7
commented
Jan 29, 2021
yup, the PR of snyk always deletes the dependencies about |
Koooooo-7
commented
Jan 29, 2021
I guess we need move the |
The reason I closed #1470 was because it was out of date, 4 versions behind |
sy-records
commented
Jan 29, 2021
Maybe snyk doesn't recognize this style https://github.com/docsifyjs/docsify/blob/develop/package.json#L106-L107 |
jhildenbiddle
commented
Feb 4, 2021
@sy-records -- Let's ping Snyk and let them know that their system appears unable to determine when two versions of the same library are listed as dependencies. Otherwise we're just going to run into this issue over and over again. Sounds like @anikethsaha maintains our account? |
anikethsaha
commented
Feb 5, 2021
I think @sy-records does have the access, right ? |
sy-records
commented
Feb 5, 2021
I private messaged you in discord @anikethsaha |
Replace #1470