Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: vulnerability fix - upgrade react-flow #8853

Merged
merged 11 commits into from May 10, 2024

Conversation

luvkapur
Copy link
Member

@luvkapur luvkapur commented May 3, 2024

This PR upgrades the react-flow library from v8 to v11 (reactflow)
v8 of react-flow lib had a vulnerability because of its dependency on [email protected]
[email protected] is vulnerable to ReDoS (GHSA-36jr-mh4h-2g58)

This PR also updates the layout of the graph in the workspace to be aligned with how it renders on bit cloud.

Deps Graph
Screenshot 2024-05-03 at 2 21 04 PM

Deps Compare Graph
Screenshot 2024-05-03 at 3 18 29 PM

@luvkapur luvkapur marked this pull request as draft May 3, 2024 17:17
@luvkapur luvkapur marked this pull request as ready for review May 3, 2024 18:25
@luvkapur luvkapur requested a review from GiladShoham May 5, 2024 15:51
@luvkapur luvkapur enabled auto-merge (squash) May 9, 2024 18:00
@luvkapur luvkapur disabled auto-merge May 9, 2024 18:03
@luvkapur luvkapur enabled auto-merge (squash) May 10, 2024 00:03
@luvkapur luvkapur merged commit 1663f16 into master May 10, 2024
11 checks passed
@luvkapur luvkapur deleted the react-flow-renderer-upgrade branch May 10, 2024 00:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants