Skip to content

Bump cross-spawn from 7.0.3 to 7.0.6#3898

Merged
tdonohue merged 1 commit intoDSpace:mainfrom
tdonohue:bump_cross-spawn
Jan 24, 2025
Merged

Bump cross-spawn from 7.0.3 to 7.0.6#3898
tdonohue merged 1 commit intoDSpace:mainfrom
tdonohue:bump_cross-spawn

Conversation

@tdonohue
Copy link
Member

@tdonohue tdonohue commented Jan 24, 2025

References

Description

This PR simply bumps the version of cross-spawn specified in our package-lock.json to avoid CVE-2024-21538. cross-spawn is only used in development, so it's unlikely this CVE would impact DSpace in production. However, bumping up just in case.

It's a port of #3894 and #3895 to main.

@tdonohue tdonohue added the dependencies Pull requests that update a dependency file label Jan 24, 2025
@tdonohue tdonohue added this to the 9.0 milestone Jan 24, 2025
@tdonohue
Copy link
Member Author

👍 Passes all tests

@tdonohue tdonohue merged commit 89b72b9 into DSpace:main Jan 24, 2025
15 checks passed
@tdonohue tdonohue deleted the bump_cross-spawn branch January 24, 2025 18:51
4science-it pushed a commit to 4Science/dspace-angular that referenced this pull request Dec 16, 2025
[DSC-2608] refactor truncatable part check

Approved-by: Giuseppe Digilio
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

No open projects
Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

1 participant