Skip to content

Conversation

@iFergal
Copy link
Collaborator

@iFergal iFergal commented Nov 20, 2025

audit-ci was only complaining about critical vulnerabilities but I would rather know about them all and ignore on a case-by-case basis. I will be re-evaluating the e2e test ones a bit closer later, as I think many of them can go away by bumping the appium server and related deps.

@iFergal iFergal self-assigned this Nov 20, 2025
@iFergal iFergal requested a review from jorgenavben as a code owner November 20, 2025 17:09
@iFergal iFergal marked this pull request as draft November 20, 2025 17:10
@iFergal iFergal marked this pull request as ready for review November 20, 2025 17:19
@iFergal iFergal requested review from rcmorano and removed request for jorgenavben and sdisalvo-crd November 20, 2025 17:20
"web-vitals": "^2.1.4"
},
"devDependencies": {
"@capacitor/assets": "^3.0.5",
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sdisalvo-crd @Sotatek-DukeVu @jorgenavben I'm removing this, and we can instead have whoever is periodically updating the assets to install this globally on their machine - it's not worth including as an additional dependency (which I would like to work on stripping down as we have a mountain of them right now)

}
}
"GHSA-2p57-rm9w-gvfp", // SSRF attacks not relevant to our usage of Meerkat
"GHSA-4hjh-wcwx-xvwj", // e2e tests
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I intend on re-evaluating some of these properly in case they pose some risk, even if a dev dependency. But I think it's easier to just blanket update appium and all related e2e dependencies tomorrow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants