Fix high and critical vulnerabilities #630
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What this PR does / why we need it?
Fix high and critical vulnerabilities
Any background context you want to provide?
These vulnerabilities came from
istanbul-instrumenter-loader
(this library turn into archeived repository). So I updated the new version. However, it is broken when installing packages(npm install
) because we use webpack 5 but this library still requires webpack 4.I saw some open source replace other alternative Istanbul loader(JS-DevTools/coverage-istanbul-loader#8). So I replace from
istanbul-instrumenter-loader
tocoverage-istanbul-loader
(DataDog/browser-sdk#1023)Reference: JS-DevTools/coverage-istanbul-loader#8
webpack-contrib/istanbul-instrumenter-loader#110
https://www.npmjs.com/package/coverage-istanbul-loader
What are the relevant tickets?
Fixes #628
Checklist