Closed mm-prodsec-bot closed 3 months ago
@mm-prodsec-bot: Adding the "do-not-merge/release-note-label-needed" label because no release-note block was detected, please follow our release note process to remove it.
@enzowritescode @esarafianou Can we find a way to stop PRs being opened by this bot for packages we can't upgrade (like this one)?
@devinbinnie I'll make a Jira issue to look into this. Not sure when we will get to it.
@devinbinnie I'll make a Jira issue to look into this. Not sure when we will get to it.
Can we remove the bot then if it's not going to be fixed anytime soon? Right now it's just a pain to have to close the PR everytime.
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.json
package-lock.json
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-BOOTSTRAP-7444593
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: 🧐 View latest project report 📜 Customise PR templates 🛠 Adjust project settings 📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS)