mi6 / mi6/ic-ui-kit

Reduce dependabot vulnerabilities

Open
#4,508 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
53
Forks
63
Avg merge
2d 4h
Merged PRs (30d)
15

Description

### Summary

Image

Currently there's 89 dependabot vulnerabilities. It used to be around 20 I think so it's really increased. We should go through and remove as many as possible.

### 💬 Description

We should prioritise the critical (1) and high (34) vulnerabilities, but there's also moderate (49) and low (5) which would be good to get rid of. Ideally this would be at 0, but just removing some of the major ones would be a good step.

### 🚨 Urgency (low, medium or high)

None

### Why do we need it?

To have more confidence in the security of our repo.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the repository's Dependabot vulnerability list, prioritising the 1 critical and 34 high-severity findings. Inspect the dependency manifests and determine which updates or remediations are safe to apply. Done means materially reducing the alert count, especially critical and high vulnerabilities, while preserving the project's existing behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.