Page MenuHomePhabricator

Review dependabot report
Closed, ResolvedPublic

Description

I think these are false positives as we don't use all those .lock files -but we should check & potentially do a housekeeping update

https://github.com/wikimedia/wikimedia-fundraising-crm-vendor/security/dependabot

Event Timeline

Reviewed! All of these are in composer.lock files in subdirectories (and in one case a package.lock version in a subdirectory). We have updated versions of the PHP libraries at the top level.

greg assigned this task to Ejegg.
greg set the point value for this task to 1.
Dwisehaupt removed the point value for this task.Nov 9 2022, 8:37 PM
Dwisehaupt set Final Story Points to 1.