Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): ua-parser-js resolution for docs #733

Merged
merged 3 commits into from
Oct 26, 2021

Conversation

TarikGul
Copy link
Member

@TarikGul TarikGul commented Oct 24, 2021

rel: #536

Set a resolution for ua-parser-js, this makes sure no affected/malicious version of ua-parser-js is downloaded inside of sidecar.

Sidecar is not affected by the following hack of ua-parser, but we also want to ensure safety and make sure no downstream deps can install the malicious versions.

docs/package.json Outdated Show resolved Hide resolved
@TarikGul TarikGul merged commit 8cfe930 into master Oct 26, 2021
@TarikGul TarikGul deleted the tarik-uaparser-resolution branch October 26, 2021 02:29
This pull request was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants