Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

41 security alerts by dependabot #3086

Closed
chgiesse opened this issue Nov 20, 2024 · 1 comment
Closed

41 security alerts by dependabot #3086

chgiesse opened this issue Nov 20, 2024 · 1 comment

Comments

@chgiesse
Copy link

Hi there!

I've forked Dash and turned on dependabot security alerts, which triggered 41 alerts. Is this due to the dev branch?

Thanks in advance and kind regards,
Christian

Image

@T4rk1n
Copy link
Contributor

T4rk1n commented Nov 25, 2024

Is this due to the dev branch?

No, we have multiple packages and the js ecosystem for them has ton of dev dependencies that get hit with alerts. Most of them are not exploitable since they are only for bundling, I usually update the importants one before releasing new version, but some of them we can't easily do (eg: Markdown in dcc need a overhaul of the markdown component).

Then there are all those in the @plotly packages, they are not part of the framework but only used for testing purpose and we don't update them as often.

@T4rk1n T4rk1n closed this as completed Nov 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants