Skip to content

Conversation

@jmaher409
Copy link
Contributor

No description provided.

The ip package is not maintained. Neoip is a new replacement that is compatible.

This is done as a resolution to a git url until all downstream dependencies that lead to ip are updated by their maintainers
We had transitive dependencies on two vulnerable versions of
path-to regexp:

The dependency via sinon was a compatible upgrade so could be fixed
via `yarn up -R path-to-regexp`.

The dependency via storybook was resolved by auto upgrading
storybook via the storybook upgrade tool.
@kermitapp
Copy link

kermitapp bot commented Dec 27, 2024

@github-actions
Copy link
Contributor

Released prerelease version 8.14.2-FEE-861-CVEs-in-react-gears-16cf56e.0.
You may now run npm install @appfolio/react-gears@FEE-861-CVEs-in-react-gears

@jmaher409 jmaher409 merged commit 25803bc into master Jan 3, 2025
4 checks passed
@jmaher409 jmaher409 deleted the FEE-861-CVEs-in-react-gears branch January 3, 2025 21:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants