Skip to content

Updates to python/npm packages to address security updates#967

Merged
sfisher merged 1 commit intodevelopfrom
dec-security-updates
Dec 4, 2025
Merged

Updates to python/npm packages to address security updates#967
sfisher merged 1 commit intodevelopfrom
dec-security-updates

Conversation

@sfisher
Copy link
Copy Markdown
Contributor

@sfisher sfisher commented Dec 3, 2025

These are the latest security updates that dependabot is flagging for December. A bump in the django version and an npm update.

The NPM update was easy to do so I did it, even though no npm libraries are used directly on the EZID site and npm/gulp is just use for compiling assets outside of what runs in the application.

@briri I'm going to tag you to review since Dave is getting busy with other things and Jing is out. The branch is already deployed to dev/stg and I can give you the login info out of band if it's helpful.

@sfisher sfisher requested a review from briri December 3, 2025 19:46
@sfisher sfisher changed the title Updates to pip/npm packages to address security updates Updates to python/npm packages to address security updates Dec 3, 2025
Copy link
Copy Markdown

@briri briri left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems pretty straightforward to me @sfisher

I'm not super familiar with Poetry, but from what I see its mostly pretty minor patches for most of the dependencies. If the site seems to be running ok to you then I'm sure its fine.

I'm not super familiar with the UI, so not sure having me login and poke around would be more useful. Happy to do so though if you want

@sfisher sfisher changed the base branch from main to develop December 4, 2025 21:00
@sfisher sfisher merged commit 28f0eeb into develop Dec 4, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants