Repository navigation
Wiz: Upgrade multiple dependencies (resolves 6 findings) - #1690
wiz-code-21c5ec5a85[bot] wants to merge 1 commit into
Conversation
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
🔗 Preview Mode
|
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
Wiz Scan Summary
To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 58cb767c90
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| "js-yaml": "4.3.2", | ||
| "json-schema-merge-allof": "^0.8.1", | ||
| "lodash-es": "^4.17.21", | ||
| "lodash-es": "4.18.0", |
There was a problem hiding this comment.
Regenerate the pnpm lockfile for these upgrades
The committed pnpm-lock.yaml still specifies js-yaml: ^4.1.1 at 4.1.1 and lodash-es: ^4.17.21 at 4.17.23. In CI, .github/actions/setup-pnpm/action.yml:35 runs plain pnpm install; pnpm documents that frozen-lockfile mode is enabled by default in CI and installation fails when the lockfile needs an update. Consequently, every workflow using this shared setup action will stop before its tests, build, or indexing steps, and the intended patched packages will not be installed. Regenerate and commit pnpm-lock.yaml with these manifest changes.
Useful? React with 👍 / 👎.
Wiz has created this PR to fix 6 findings detected in this project
Changes were made to the following file(s):
package.jsonVulnerabilities:
4.1.1 → 4.3.2
/package.json4.17.23 → 4.18.0
/package.jsonTo detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio.