Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Closes #684
I think this addresses the main
npm audit
/ dependabot issues, except for one inknex
.I've looked into the knex issue a bit more. It would be a big jump for us (0.21 to 2.4.1) and it looks like one of the changes is how many select and insert/returning queries now return dicts instead of values, e.g.,
{id: 1}
instead of1
, which would affect many of our migrations. We also don't have a great way to find where this change is necessary and test all the migrations.The vulnerability itself is around the
WHERE
clause, and this page shows an example exploit where request data is used in a where clause. We're not using knex with request data, and our where clauses in the migrations are also pretty locked down (they tend to be ids or hardcoded strings) so I think this vulnerability has minimal impact on us.What has been done to verify that this works as intended?
Tests still pass,
npm audit
complains less.Before submitting this PR, please make sure you have:
make test-full
and confirmed all checks still pass OR confirm CircleCI build passes