USWDS - Bump stylelint, @18f/identity-stylelint-config, and postcss #5373
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Bump
stylelint,@18f/identity-stylelint-config, andpostcssto resolve semver vulnerability.Breaking change
This is not a breaking change.
Related issue
Closes Dependabot alert #61
Related pull requests
Dependabot Security Update #5366
Preview link
Preview link:
USWDS →
Problem statement
Stylelinthas vulnerability in semver dependency.Updating this dependency alone causes conflicts with
@18f/identity-stylelint-configwhich, when updated alone, causes a conflict withPostcssSolution
Bump
stylelintand relevant dependencies that are needed in order to prevent errors.stylelint 14.13.0 → 15.10.1@18f/identity-stylelint-config 1.0.0 → 2.0.0postcss 8.4.0 → 8.4.19Dependency updates
Testing and Review
npm installand confirm no installation errorsnpm run lint:sassnpm run startTesting checklist
git pull origin [base branch]to pull in the most recent updates from your base and check for merge conflicts. (Often, the base branch isdevelop).npm run prettier:sassto format any Sass updates.npm testand confirm that all tests pass.