bcgov / foi-flow

Freedom of Information modernization
Apache License 2.0
4 stars 3 forks source link

Dependabot (critical/High) - forms-flow-web #4777

Open antsand opened 7 months ago

antsand commented 7 months ago

Dependabot link - https://github.com/bcgov/foi-flow/security/dependabot?q=is%3Aopen+manifest%3Aforms-flow-web%2Fpackage-lock.json

Upgrade to latest version of Nodejs before addressing these

antsand commented 5 months ago

After upgrading to Node 20, clearing a few unused packages and upgrading some critical packages all the high and critical dependabots are fixed.

antsand commented 5 months ago

Though there is no vulnerability related to React, it will be good to upgrade React to v18 after this dependabot fix