fix: harden frontend-builder with npm upgrade to mitigate bundled CVEs
This commit is contained in:
@@ -28,9 +28,8 @@ else
|
||||
--config p/react
|
||||
--config p/secrets
|
||||
--config p/dockerfile
|
||||
--config p/bash
|
||||
)
|
||||
echo "Running Semgrep with configs: p/golang, p/javascript, p/typescript, p/react, p/secrets, p/dockerfile, p/bash"
|
||||
echo "Running Semgrep with configs: p/golang, p/javascript, p/typescript, p/react, p/secrets, p/dockerfile"
|
||||
fi
|
||||
|
||||
semgrep scan \
|
||||
|
||||
Reference in New Issue
Block a user