Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade dependencies to fix CVEs and setup a dependabot/renovate-like solution #131

Open
3 tasks
thomvaill opened this issue Oct 30, 2024 · 0 comments
Open
3 tasks
Labels
maintenance Maintenance tasks
Milestone

Comments

@thomvaill
Copy link
Owner

  • Upgrade dependencies to fix CVEs (except Next.js which is a separate issue) thanks to yarn upgrade-interactive, like what was started in Upgrade dependencies  #115 (thank you @ezavgorodniy)
  • Configure the Security tab in Github (-> @thomvaill)
  • Assess and implement one of the dependabot/renovate-like solutions if possible so that we have a procedure in place to fix the upcoming CVEs
@thomvaill thomvaill added feature New feature or request maintenance Maintenance tasks and removed feature New feature or request labels Oct 30, 2024
@thomvaill thomvaill added this to the v1.1.0 milestone Oct 30, 2024
@thomvaill thomvaill modified the milestones: v1.1.0, v1.2.0 Dec 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
maintenance Maintenance tasks
Projects
None yet
Development

No branches or pull requests

1 participant