Skip to content

Upgrade css-nano and mocha to fix security issues #1

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Mar 27, 2019

Conversation

skogsmaskin
Copy link
Member

@skogsmaskin skogsmaskin commented Mar 27, 2019

What kind of change does this PR introduce?

Update cssnano and mocha to fix npm security issues

Did you add tests for your changes?

Ran tests, there was one test failing and that was the keyframe-test. Didn't seem like anything important though. A comment was removed from the new output, and a bit more compacted (I guess cssnano just does it's job better). I also symlinked the module to test againt a studio. Could not see any issues.

If relevant, did you update the README?
Not relevant.

Summary
Updated cssnano to avoid https://nodesecurity.io/advisories/788

Does this PR introduce a breaking change?

No

Other information
Also upgraded mocha to latest version because there were some security issues there as well.

Copy link
Member

@bjoerge bjoerge left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@skogsmaskin skogsmaskin merged commit 3715587 into master Mar 27, 2019
@skogsmaskin skogsmaskin deleted the upgrade-cssnano branch March 27, 2019 12:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants