Repository navigation
Wiz: Upgrade multiple dependencies (resolves 6 findings) - #1694
wiz-code-21c5ec5a85[bot] wants to merge 1 commit into
Conversation
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
🔗 Preview Mode
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cb7eaa60d5
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| "js-yaml": "4.3.2", | ||
| "json-schema-merge-allof": "^0.8.1", | ||
| "lodash-es": "^4.17.21", | ||
| "lodash-es": "4.18.0", |
There was a problem hiding this comment.
Commit the updated pnpm lockfile
These dependency specifiers were changed without updating pnpm-lock.yaml, whose root importer still requests js-yaml: ^4.1.1 and lodash-es: ^4.17.21. The workflows using .github/actions/setup-pnpm/action.yml run pnpm install; pnpm 10 enables frozen-lockfile mode in CI and fails when the lockfile and manifest are out of sync (pnpm install documentation). Consequently, the PR-check, deployment, and indexing workflows fail during dependency setup, so the regenerated lockfile must be committed with these changes.
Useful? React with 👍 / 👎.
Wiz has created this PR to fix 6 findings detected in this project
Changes were made to the following file(s):
package.jsonVulnerabilities:
4.1.1 → 4.3.2
/package.json4.17.23 → 4.18.0
/package.jsonTo detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio.