<#1217 CVE check denying ramda@0.28.0 which is dep...
# pact-js-development
g
#1217 CVE check denying ramda@0.28.0 which is dependent on by pact-foundation/pact Issue created by julielaursen Software versions Please provide at least OS and version of pact-js • OS: Mac OS Sonoma 14.5 • Consumer Pact library: @pact-foundation/pact 12.5.0 • Node Version: v18.20.2 Issue Checklist Please confirm the following: ☑︎ I have upgraded to the latest ☑︎ I have the read the FAQs in the Readme ☑︎ I have triple checked, that there are no unhandled promises in my code and have read the section on intermittent test failures Expected behaviour Pact should not cause issues in Fossa vulnerability scanning software Actual behaviour In our Fossa step in CI, we are getting this error
Copy code
This license is denied by your licensing policy.
This issue exists in a transitive dependency.
for version ramda (0.28.0) When i run
yarn why ramda
I get:
Copy code
├─ @pact-foundation/pact@npm:12.5.0
│  └─ ramda@npm:0.28.0 (via npm:^0.28.0)
│
I suspect this may be the same issue as #962 and #880 Because Fossa is required in CI, this blocks our CI for all PRs moving forward pact-foundation/pact-js