[DDW-1149] Update part of vulnerable packages #3120
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR updates some of the packages that contain critical and high-severity vulnerabilities. Here is the list of the packages that did not get updated and can be treated as separate task:
Development deps, should not be impacting build (considered lower priority):
dns-packet
used bywebpack-dev-server
ua-parser-js
used bystorybook
decode-uri-component
used by@testing-library
source maps, etc.glob-parent
used bygulp
,eslint
andstorybook
High risk and high/unknown upgrade effort:
http-cache-semantics
used byelectron
json5
used by many packages e.g.svg-inline-loader
,storybook
,eslint-plugin-import
(svg-inline-loader is no longer maintained)d3-color
used byrecharts
terser
used by@storybook
andwebpack
(we already have the latest version ofwebpack
)Testing Checklist
Review Checklist
Basics
input-output-hk/daedalus-dev
andinput-output-hk/daedalus-qa
assigned as PR reviewersrun Chromatic
label to PR to trigger the run)release-vNext
,feature
/bug
/chore
,WIP
)yarn manage:translations
produces no changes)yarn storybook
)yarn.lock
file is updatedCode Quality
Testing
After Review