Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove unused is-svg yarn dependency #2931

Merged
merged 1 commit into from
Aug 2, 2024
Merged

Remove unused is-svg yarn dependency #2931

merged 1 commit into from
Aug 2, 2024

Conversation

jesszzzz
Copy link
Contributor

Motivation

Git flagged fast-xml-parser as a security vulnerability (https://github.com/facebookresearch/hydra/security/dependabot/84). It's being brought in as part of is-svg which isn't even being used (code search). Hence I'm removing is-svg from the dependencies list, and also ran yarn to update the yarn.lock file.

Have you read the Contributing Guidelines on pull requests?

Yes

Test Plan

Ran yarn start and clicked around the website to verify it looks ok

Related Issues and PRs

https://github.com/facebookresearch/hydra/security/dependabot/84

@facebook-github-bot facebook-github-bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Jul 29, 2024
Copy link

@tonykao8080 tonykao8080 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good

@jesszzzz jesszzzz merged commit de47f41 into main Aug 2, 2024
61 checks passed
@jesszzzz jesszzzz deleted the remove-is-svg-dep branch August 5, 2024 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants