Repository navigation
Conversation
Signed-off-by: axi92 <axi92@users.noreply.github.com>
crazy-max
left a comment
There was a problem hiding this comment.
Thanks but that's something that needs to be addressed upstream first as these are peer dependencies.
| "@actions/io": "^1.1.3", | ||
| "@actions/tool-cache": "^2.0.2", | ||
| "@azure/storage-blob": "^12.15.0", | ||
| "@azure/storage-blob": "^12.28.0", |
There was a problem hiding this comment.
We want to be aligned with upstream @actions/cache module: https://github.com/actions/toolkit/blob/f58042f9cc16bcaa87afaa86c2974a8c771ce1ea/packages/cache/package.json#L48. We already made the mistake to update to 12.15.0 while 12.13.0 is used by this module.
If updates are needed, open a PR on https://github.com/actions/toolkit first.
| "form-data@^4.0.0": "4.0.4", | ||
| "form-data@^3.0.0": "3.0.4", | ||
| "semver@^6.3.0": "6.3.1", | ||
| "semver@^6.1.0": "6.3.1", | ||
| "brace-expansion@^2.0.1": "2.0.2", | ||
| "@octokit/request@^8.0.2": "8.4.1", | ||
| "@octokit/request@^8.0.1": "8.4.1", | ||
| "@octokit/request@^8.1.1": "8.4.1", | ||
| "@octokit/request-error@^5.0.0": "5.1.1" |
There was a problem hiding this comment.
Same here, these are peer dependencies that need to be addressed upstream first: https://github.com/actions/toolkit
See transitive dep in https://github.com/docker/actions-toolkit/security/dependabot/35 for example:
Goal of this PR: resolve as much CVEs as possible
Scan tool used: Trivy
Before
After
I ran the tests: https://github.com/axi92/actions-toolkit/actions/runs/17286861753
I tried to patch with yarns resolutions as much as possible without breaking semver.
If this approach is not the desired one I am open to other changes.