Closed melvin-bot[bot] closed 1 year ago
This is a Snyk issue. Snyk is a tool that automatically tracks our repositories' dependencies and reports associated security vulnerabilities. It also automatically create PRs to fix these vulnerabilities.
C+: Please follow these steps to test the linked PR before running through the reviewer checklist:
- [ ] The first step is to understand the PR: what dependency is it upgrading, for which vulnerability, how it impacts our product & end users.
- [ ] If the issue is not worth fixing, please add your reasoning in the issue and have the internal engineer review it.
- [ ] Check the change log (which should be included in the PR description) to see all changes. We want to identify any breaking changes. If it is a minor version bump, it's unlikely that there are any breaking changes.
- [ ] Test our feature(s) that make use of this package. If it does not work, we should understand what broke it. It is also a good idea to check our main flows to make sure they are not broken that you can add in the checklist screenshots/videos.
Job added to Upwork: https://www.upwork.com/jobs/~013e6c354c4810571c
Triggered auto assignment to Contributor Plus for review of internal employee PR - @aimane-chnaif (Internal
)
Reviewing
label has been removed, please complete the "BugZero Checklist".
The solution for this issue has been :rocket: deployed to production :rocket: in version 1.3.12-0 and is now subject to a 7-day regression period :calendar:. Here is the list of pull requests that resolve this issue:
If no regressions arise, payment will be issued on 2023-05-16. :confetti_ball:
After the hold period is over and BZ checklist items are completed, please complete any of the applicable payments for this issue, and check them off once done.
As a reminder, here are the bonuses/penalties that should be applied for any External issue:
@aimane-chnaif Uh oh! This issue is overdue by 2 days. Don't forget to update your issues!
@stitesExpensify can you please add BZ member for me?
Triggered auto assignment to @tjferriss (External
), see https://stackoverflow.com/c/expensify/questions/8582 for more details.
Current assignee @aimane-chnaif is eligible for the External assigner, not assigning anyone new.
Triggered auto assignment to @thienlnam (External
), see https://stackoverflow.com/c/expensify/questions/7972 for more details.
@tjferriss This issue is ready for payment - internal review to @aimane-chnaif
@tjferriss, @thienlnam, @aimane-chnaif Uh oh! This issue is overdue by 2 days. Don't forget to update your issues!
Bump when you get the chance @tjferriss
@aimane-chnaif the offer is pending your acceptance: https://www.upwork.com/jobs/~0168b695076da79b8d.
@tjferriss, @thienlnam, @aimane-chnaif Whoops! This issue is 2 days overdue. Let's get this updated quick!
@aimane-chnaif has been paid.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Mature exploit, Recently disclosed, Has a fix available, CVSS 7.6
SNYK-JS-ELECTRON-5462056
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: π§ View latest project report
π Adjust project settings
π Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
π¦ Learn about vulnerability in an interactive lesson of Snyk Learn.
Upwork Automation - Do Not Edit