Skip to content

Dependabot fixes#349

Open
goldsmithb wants to merge 2 commits intomainfrom
dependabot-fixes
Open

Dependabot fixes#349
goldsmithb wants to merge 2 commits intomainfrom
dependabot-fixes

Conversation

@goldsmithb
Copy link
Contributor

This PR addresses a number of critical/high dependabot security alerts:

Critical Issues resolved:

High Issues resolved:

Moderate Issues resolved:

This is mostly dependency management.

What was done:

  • specify fugit gem version
  • bump up nokogiri version
  • specify resque-scheduler version
  • remove "resolve-url-loader" node package (and dependencies) (this was needed when we used webpack but no longer with Vite!)

@JackBlackLight
Copy link
Contributor

@goldsmithb, there's a merge conflict on this branch and I think we just want to remove the two lines from package.json but I wanted to doublecheck with you to make sure. Thanks for this PR btw!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants