neulab / explainaboard_web

MIT License
8 stars 2 forks source link

Fixed production dependency vulnerabilities #547

Closed PaulCCCCCCH closed 1 year ago

PaulCCCCCCH commented 1 year ago

All prod vulnerabilities are fixed in this PR. Details:

Note:

react-code-blocks and firebase depend on vulnerable library versions, and there are no updates available. Thus, we will use overrides as a temperary solution. However, this is generally not considered a good practice according to ChatGPT (see below). We should update the packages and remove the overrides once these packages are updated.

screencapture-chat-openai-chat-2022-12-05-21_31_28