Skip to content
This repository was archived by the owner on Sep 29, 2023. It is now read-only.

Dependabot json #13

Merged
merged 3 commits into from
Jul 1, 2021
Merged

Dependabot json #13

merged 3 commits into from
Jul 1, 2021

Conversation

stevenjonescgm
Copy link
Contributor

address https://github.com/RepairShopr/importr/security/dependabot/Gemfile.lock/json/open CVE-202-10663 by removing sdoc and therfore json

also remove unused jbuilder and try to find a sassc that does not take minutes to compile

@@ -30,6 +30,7 @@ gem 'sidekiq'
gem 'puma'

# Use SCSS for stylesheets
# NOTE: dependency gem sass-rails => gem sassc => native `libsass` which may take minutes to compile
Copy link
Contributor

@gryaznov gryaznov Jul 1, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we don't need this gem either?
I cannot find any sass/scss files in the project. Rules in app/assets/stylesheets are regular .css. Third-party libs (e.g. bootstrap) live in vendor/assets and rely on their own stylesheets with their own builds.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we do have *.scss files in this project
image

I'm not inclined to spend time to test removing sass-rails until we experience a practical problem with it.

@pamelalucinda pamelalucinda merged commit f4621ac into master Jul 1, 2021
@pamelalucinda pamelalucinda deleted the dependabot-json branch July 1, 2021 21:13
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants