chore: reduce high severity yarn audit findings#347
Conversation
79dbda2 to
1fae4b8
Compare
1fae4b8 to
e1c7e1d
Compare
|
Rebased onto current Verification after rebase:
GitHub reports the branch as mergeable now; current blocked state appears to be review/check gating rather than conflicts. |
brh28
left a comment
There was a problem hiding this comment.
What kind of testing has been done to ensure no regression?
iOS and Android smoke testing of maps screens, send, receive, settings, chat, camera. |
Ledger test results for the
|
Summary
axios,express,body-parser,cookie,jsonwebtoken,mongoose,@google-cloud/storage,@grpc/proto-loader, etc.)Audit impact
Before:
After:
yarn audit --level highemits no high/critical advisoriesVerification
Rebased on current
mainafter #346.yarn install --frozen-lockfile✅yarn build✅yarn tsc-check-noimplicitany✅yarn tsc-check✅npx prettier --check package.json✅yarn audit --level high✅ no high/critical advisoriesNotes
yarn audit --level highexits non-zero because Yarn v1 reports remaining low/moderate advisories in the summary, but the JSON audit stream contains no high/criticalauditAdvisoryentries.ln-service,spectaql,api/oas, and older toolchain packages.