Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Move file-loader to dev-dependencies #2556

Merged
merged 1 commit into from
Aug 10, 2021

Conversation

timotheeg
Copy link
Contributor

Context

Snyk is reporting an issue with an outdated version of ajv, which is reported as a sub dependency of [email protected].

This is a false positive however, due to an incorrect categorisation of the dependency. file-loader is a webpack module and is thus a dev-dependency which should not be reported by Snyk.

Approach

Move dependency to dev-dependency instead.

Note: [email protected] is 2 major versions behind (latest is 6.2.0 a the time of this PR), because our webpack tooling on FormSG is very much outdated. At some point, we should upgrade the whole tool chain to benefit from whatever improvements and optimisations are being released.

@timotheeg timotheeg merged commit 883f842 into develop Aug 10, 2021
@timotheeg timotheeg deleted the file_loader_is_dev_dependency branch August 10, 2021 04:05
@karrui karrui mentioned this pull request Aug 11, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants