Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

ci: restore stylelint, ignore micromatch CVE #639

Merged
merged 2 commits into from
Aug 22, 2024
Merged

Conversation

ppvg
Copy link
Member

@ppvg ppvg commented Aug 22, 2024

This PR reverts #638 and adds an auditConfig to ignore CVE-2024-4067 (GHSA-952p-6rrq-rcjv), which is for a vulnerability in micromatch, a nested dependency of stylelint. This does not run in production. It does run in CI, but as far as I can tell stylelint does not hit micromatch's vulnerable code path (it doesn't call micromatch.parse or micromatch.braces).

Closes: #637

@ppvg ppvg requested a review from a team as a code owner August 22, 2024 10:10
@ppvg ppvg merged commit 718011b into main Aug 22, 2024
9 checks passed
@ppvg ppvg deleted the ci/restore-stylelint branch August 22, 2024 10:13
@ppvg ppvg mentioned this pull request Aug 26, 2024
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Restore CSS linting
2 participants