Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Questions
Summary
This ticket upgrades draftail to the most recent version, but even it requires the draft-js version in this vulnerability.
Draftail powers our page admin interface so is inside the locked admin area.
Complications:
More complications:
We may need to look into a new editor as there hasn't been a Draftail update since August 2019. There's an issue from August 2020 asking whether the Draftail project is dead with no replies
dependency tree: [email protected] › [email protected] › [email protected] › [email protected]
Impacted areas of the application
Our site admin editor
Screenshots
Should be no visible changes
Related PRs
None
How to test
npm i
npm run build-production
./manage.py runserver
snyk test
still lists the vulnerability is [Snyk: Medium] package.json - Denial of Service (due 11/16/20) #4043