Github security concern related to phoenix 1.4 app

ok,

$ mix phx.new -v
Phoenix v1.4.10
$ mix phx.new koko
$ cd koko/assets
$ npm outdated
Package                             Current  Wanted  Latest  Location
copy-webpack-plugin                   4.6.0   4.6.0   5.0.5  global
css-loader                            2.1.1   2.1.1   3.2.1  global
mini-css-extract-plugin               0.4.5   0.4.5   0.8.0  global
optimize-css-assets-webpack-plugin    4.0.3   4.0.3   5.0.3  global
uglifyjs-webpack-plugin               1.3.0   1.3.0   2.2.0  global
webpack                               4.4.0   4.4.0  4.41.2  global
webpack-cli                           2.1.5   2.1.5  3.3.10  global

returns the list of outdated packages, then just update the versions of packages You want in packages.json and run npm install.

4 Likes