Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Temporarily ignore advisory #27676

Merged
merged 1 commit into from
Oct 8, 2024

Conversation

Gudahtt
Copy link
Member

@Gudahtt Gudahtt commented Oct 7, 2024

Description

The advisory GHSA-593m-55hh-j8gv has been temporarily ignored, just for v12.4.x. This is resolved by a dependency update in v12.5.0, but the update included too many functional changes, so we deemed it too risky to backport in this release.

The impact is expected to be negligable due to our use of LavaMoat and SES lockdown.

Open in GitHub Codespaces

Related issues

The audit advisory was resolved here on develop: #27620

And it was back ported to v12.5.0 here: #27673

Manual testing steps

N/A

Screenshots/Recordings

N/A

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

The advisory GHSA-593m-55hh-j8gv has been
temporarily ignored, just for v12.4.x. This is resolved by a dependency
update in v12.5.0, but the update included too many functional changes,
so we deemed it too risky to backport in this release.

The impact is expected to be negligable due to our use of LavaMoat and
SES lockdown.
@Gudahtt Gudahtt force-pushed the audit-advisory-temporarily-ignore branch from 7f8938d to 63509c9 Compare October 7, 2024 17:18
@Gudahtt Gudahtt marked this pull request as ready for review October 7, 2024 17:22
@Gudahtt Gudahtt requested a review from a team as a code owner October 7, 2024 17:22
Copy link

codecov bot commented Oct 7, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 70.06%. Comparing base (fabf62d) to head (63509c9).

Additional details and impacted files
@@               Coverage Diff                @@
##           Version-v12.4.0   #27676   +/-   ##
================================================
  Coverage            70.06%   70.06%           
================================================
  Files                 1422     1422           
  Lines                49693    49693           
  Branches             13892    13892           
================================================
  Hits                 34815    34815           
  Misses               14878    14878           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@metamaskbot
Copy link
Collaborator

Builds ready [63509c9]
Page Load Metrics (1779 ± 75 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint21620931711377181
domContentLoaded15172016175114771
load15252027177915675
domInteractive12199414019

@Gudahtt Gudahtt merged commit c8f966c into Version-v12.4.0 Oct 8, 2024
74 checks passed
@Gudahtt Gudahtt deleted the audit-advisory-temporarily-ignore branch October 8, 2024 15:49
@github-actions github-actions bot locked and limited conversation to collaborators Oct 8, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants