Reduce dependabot vulnerabilities
- Dominant language
- TypeScript
- Stars
- 53
- Forks
- 63
- Avg merge
- 2d 4h
- Merged PRs (30d)
- 15
Description
### Summary
Currently there's 89 dependabot vulnerabilities. It used to be around 20 I think so it's really increased. We should go through and remove as many as possible.
### 💬 Description
We should prioritise the critical (1) and high (34) vulnerabilities, but there's also moderate (49) and low (5) which would be good to get rid of. Ideally this would be at 0, but just removing some of the major ones would be a good step.
### 🚨 Urgency (low, medium or high)
None
### Why do we need it?
To have more confidence in the security of our repo.
Contributor guide
Research direction
Start by reviewing the repository's Dependabot vulnerability list, prioritising the 1 critical and 34 high-severity findings. Inspect the dependency manifests and determine which updates or remediations are safe to apply. Done means materially reducing the alert count, especially critical and high vulnerabilities, while preserving the project's existing behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100