SWI-3723 [Snyk] Security upgrade @actions/core from 1.11.1 to 2.0.0#1
SWI-3723 [Snyk] Security upgrade @actions/core from 1.11.1 to 2.0.0#1
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-UNDICI-14943963
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
This is a major version upgrade from 1.x to 2.x. However, there are no official release notes detailing the breaking changes for the v2.0.0 release. A GitHub issue has been raised in the official Recommendation: Given the lack of documentation for a major version change, the impact is unknown. Proceed with caution and perform manual validation before merging.
|
|
This major version upgrade of Recommendation: Ensure your self-hosted runners are updated to a version that supports the Node.js 20 runtime before using actions compiled with this library version. No specific API breaking changes have been documented. Source: Inferred from related
|
|
This major version upgrade aligns with updates across the Source: Release notes for sibling packages in the
|
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-UNDICI-14943963
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling