Conversation
3e47e88 to
92fb72b
Compare
|
Hmmm...taking a look at this now, and I think our best bet is to wait a few more days to fix. The high vulnerability is from Also, there is no fixed version of this available yet, so we need to downgrade to get a safe version. Hopefully, the gulp team will address the problem and put out a new release soon. In that case, it will be easier to fix this dependabot issue. If no fix comes in a few weeks, we should downgrade to gulp v3.9.x which is the latest safe version, though might be a bit of a pain. |
Thanks for taking a look! ✨ I'll close this PR for now, and hopefully there'll be a patched version of gulp soon 🤞🏽 |
Coming back to this now that #882 is merged 🎉
See https://github.com/github/vscode-codeql/security/dependabot. I ran
npm audit fixas a starting point, but thismight needdefinitely needs some manual work too.Checklist
N/A
@github/docs-content-codeqlhas been cc'd in all issues for UI or other user-facing changes made by this pull request.