fix: upgrade core-js to 2.6.12 #92
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
This PR addresses a vulnerability in
core-js@2.6.11by upgrading it to version2.6.12.Since
core-jsis a transitive dependency (via@babel/polyfill->auth0-extensions-cli), we have addedcore-js@2.6.12as a direct dependency inpackage.jsonto force the use of the patched version.Changes
package.jsonto add"core-js": "2.6.12"todependencies.yarn.lockto reflect the new dependency resolution.Verification
The following tests were performed to verify the fix:
yarn why core-jsto confirm thatcore-jsis resolved to2.6.12.npm run extension:buildto ensure the extension builds successfully with the new dependency.NODE_OPTIONS=--openssl-legacy-providerwas used to bypass OpenSSL legacy provider issues.Closes operational risk ticket for
core-js@2.6.11.