-
Type:
Task
-
Resolution: Unresolved
-
Priority:
Major - P3
-
None
-
Affects Version/s: None
-
Component/s: None
Currently, we have CI Security checks only applies to prod ones. We should enable third party vuln checks for dev dependencies as well, since they run in CI Sandbox, which make Workers vulnerable of exploitation via Dev Deps.
AC:
- Generate a list of dev deps that have vulns
- Enable the check on the CI for dev deps
- Create follow up tickets (after ignore them initially which tickets linked)