cc-archive / vocabulary-legacy

A cohesive design system & Vue component library to unify the web-facing Creative Commons
https://cc-vocabulary.netlify.app
MIT License
87 stars 129 forks source link

Update project dependencies to resolve vulnerability warnings (currently 113) #1021

Closed brylie closed 4 months ago

brylie commented 2 years ago

Running npm audit on the Vocabulary project warns of 113 vulnerabilities as of 2021-11-02. Granted, many of the vulnerabilities may be relatively low impact, particularly if they only pertain to devDependencies. However, we should upgrade our dependencies to reduce the warnings and improve the health of our project.

Task

brylie commented 2 years ago

@Cronus1007, would you consider helping out with this task?

Cronus1007 commented 2 years ago

@brylie Sure I will have a look upon this issue during this weekend

brylie commented 2 years ago

Thanks! I really appreciate it. :smiley:

Cronus1007 commented 2 years ago

@brylie I have started working upon this issue. Once I would be able to get major work done regarding this issue I will raise a PR.

Cronus1007 commented 2 years ago

@brylie Can you please have a look at the Github security policy of the repository since it can help me a lot to resolve this issue and also attach the screenshot of the security policy?

brylie commented 2 years ago

@Cronus1007 I'm not sure what GitHub security policy you're referring to. We have dependabot enabled on this repository.

In any case, the issue is related to the security vulnerabilities reported when running npm audit. Please review the npm audit output for further details.

ShadyResurrected commented 1 year ago

can i be assigned this issue

possumbilities commented 4 months ago

This project is moving towards being archived, and this item is no longer on the roadmap. Closing