Update npm packages. GitHub Actions should audit npm packages #165
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update npm packages to latest versions.
GitHub Actions should run yarn audit on npm packages.
Adds script/yarn_audit.sh which is run by GitHub Actions and can also be run by developer. This runs yarn audit, but accepts some known high severity warnings, mostly about potential DoS. We are relatively unaffected by these, because we run yarn install at deployment time, on our own predefined views.
The integration test failures are known flakey tests, unrelated to this commit. I've checked, and the new npm packages produce identical output to before, when running
rake assets:precompile.