Skip to content

Bumping "ip" dev dependency to latest (prevent false-positives from vulnerability scanners) #1671

@ethanae

Description

@ethanae

Is your feature request related to a problem? Please describe.
A security vulnerability for the"ip" development dependency: https://nvd.nist.gov/vuln/detail/CVE-2023-42282

Despite being "ip" listed and used only as a development dependency some image scanners, like AWS Inspector, incorrectly report images as vulnerable - not ideal but not terrible as the images are not actually at risk of this vulnerability.

Describe the solution you'd like
Bumping "ip" to its latest version, 2.0.1

Thanks.

Additional context
Non-breaking change

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions