[Snyk] Security upgrade webpack-dev-server from 3.7.1 to 4.7.3#181
[Snyk] Security upgrade webpack-dev-server from 3.7.1 to 4.7.3#181
Conversation
…duce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-NODEFORGE-14114940 - https://snyk.io/vuln/SNYK-JS-NODEFORGE-14125745 - https://snyk.io/vuln/SNYK-JS-NODEFORGE-14125097
|
|
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Important
Looks good to me! 👍
Reviewed everything up to 74e3679 in 1 minute and 9 seconds. Click for details.
- Reviewed
13lines of code in1files - Skipped
1files when reviewing. - Skipped posting
1draft comments. View those below. - Modify your settings and rules to customize what types of comments Ellipsis leaves. And don't forget to react with 👍 or 👎 to teach Ellipsis.
1. www/build_common/package.json:37
- Draft comment:
Upgraded webpack-dev-server to ^4.7.3 is a major version upgrade. Please verify that your webpack-dev-server configuration is updated in line with v4's breaking changes (e.g. config options like 'contentBase' may need to be replaced by 'static'). - Reason this comment was not posted:
Decided after close inspection that this draft comment was likely wrong and/or not actionable: usefulness confidence = 0% vs. threshold = 50% The rules explicitly state "Do NOT comment on dependency changes, library versions that you don't recognize, or anything else related to dependencies." This comment is directly about a dependency version upgrade. Even though it's a major version change with potential breaking changes, the rules are clear that dependency changes should not be commented on. Additionally, the comment asks the author to "verify" something, which violates the rule about not asking the PR author to confirm, double-check, or ensure things. While major version upgrades can introduce breaking changes that could cause real issues, the rules explicitly exclude dependency-related comments. Perhaps the rule is too broad and this type of comment about breaking changes in major versions could be valuable? Even if this could be a valuable comment in some contexts, the rules are explicit and clear: "Do NOT comment on dependency changes, library versions that you don't recognize, or anything else related to dependencies." This is unambiguously a dependency change comment. Additionally, it asks the author to "verify" which is also explicitly prohibited. This comment should be deleted because it violates two rules: it comments on a dependency change, and it asks the PR author to verify/confirm something. Both are explicitly prohibited by the review guidelines.
Workflow ID: wflow_lzYyk8sQohIsqkfk
You can customize by changing your verbosity settings, reacting with 👍 or 👎, replying to comments, or adding code review rules.
Snyk has created this PR to fix 3 vulnerabilities in the yarn dependencies of this project.
Snyk changed the following file(s):
www/build_common/package.jsonwww/build_common/yarn.lockNote for zero-installs users
If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the
.yarn/cache/directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to runyarnto update the contents of the./yarn/cachedirectory.If you are not using zero-install you can ignore this as your flow should likely be unchanged.
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-NODEFORGE-14114940
SNYK-JS-NODEFORGE-14125745
SNYK-JS-NODEFORGE-14125097
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.
Important
Upgrade
webpack-dev-serverto 4.7.3 to fix security vulnerabilities innode-forge.webpack-dev-serverfrom 3.7.1 to 4.7.3 inpackage.jsonandyarn.lock.node-forge.yarnto update.yarn/cache/if using zero-installs.This description was created by
for 74e3679. You can customize this summary. It will automatically update as commits are pushed.