#1217 CVE check denying ramda@0.28.0 which is dependent on by pact-foundation/pact
Issue created by
julielaursen
Software versions
Please provide at least OS and version of pact-js
•
OS: Mac OS Sonoma 14.5
•
Consumer Pact library: @pact-foundation/pact 12.5.0
•
Node Version: v18.20.2
Issue Checklist
Please confirm the following:
☑︎ I have upgraded to the latest
☑︎ I have the read the FAQs in the Readme
☑︎ I have triple checked, that there are
no unhandled promises in my code and have
read the section on intermittent test failures
Expected behaviour
Pact should not cause issues in Fossa vulnerability scanning software
Actual behaviour
In our Fossa step in CI, we are getting this error
This license is denied by your licensing policy.
This issue exists in a transitive dependency.
for version ramda (0.28.0)
When i run
yarn why ramda
I get:
├─ @pact-foundation/pact@npm:12.5.0
│ └─ ramda@npm:0.28.0 (via npm:^0.28.0)
│
I suspect this may be the same issue as
#962
and
#880
Because Fossa is required in CI, this blocks our CI for all PRs moving forward
pact-foundation/pact-js