Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bump cross-spawn version to 7.0.6 #3033

Merged
merged 2 commits into from
Nov 20, 2024
Merged

Conversation

bobbyu99
Copy link
Contributor

@bobbyu99 bobbyu99 commented Nov 18, 2024

Description of changes

This PR is to fix this dependabot alert. In shot, cross-spawn is used by husky and needs to be bumped to be higher than 7.0.5 for a security patch.

  • bumping husky to ^4.0.0 and cross-spawn to 7.0.6.
CDK / CloudFormation Parameters Changed

Issue #, if available

Description of how you validated changes

Checklist

  • PR description included
  • yarn test passes
  • E2E test run linked
  • Tests are changed or added
  • Relevant documentation is changed or added (and PR referenced)
  • New AWS SDK calls or CloudFormation actions have been added to relevant test and service IAM policies
  • Any CDK or CloudFormation parameter changes are called out explicitly

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@bobbyu99 bobbyu99 marked this pull request as ready for review November 18, 2024 22:39
@bobbyu99 bobbyu99 requested review from a team as code owners November 18, 2024 22:39
dpilch
dpilch previously approved these changes Nov 18, 2024
atierian
atierian previously approved these changes Nov 18, 2024
@bobbyu99 bobbyu99 dismissed stale reviews from atierian and dpilch via 386ce3b November 20, 2024 18:04
@bobbyu99 bobbyu99 merged commit 519ee9d into main Nov 20, 2024
7 checks passed
@bobbyu99 bobbyu99 deleted the bump-cross-spawn-version branch November 20, 2024 19:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants