Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump cosmiconfig to 8.x.x #1253

Merged
merged 1 commit into from
May 17, 2023

Conversation

ninadbstack
Copy link
Contributor

Changes:

  • Updated cosmiconfig to 8.x.x
  • Older version was using yaml 1.x.x which had open cve's, newer version has moved to js-yaml package as dependency
  • We still have older yaml as dependency as its a dependency of lerna as well, but as lerna is not included as dependency in final released package, it would be not distributed

@samarsault samarsault self-requested a review May 17, 2023 06:42
@ninadbstack ninadbstack merged commit 7c45dd9 into master May 17, 2023
32 checks passed
@ninadbstack ninadbstack deleted the PER-9999-update-cosmiconfig-security-update branch May 17, 2023 07:43
@ninadbstack ninadbstack added the ⬆️⬇️ dependencies Pull requests that update a dependency file label May 17, 2023
shahidk8 pushed a commit that referenced this pull request Jun 29, 2023
samarsault pushed a commit that referenced this pull request Jun 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
⬆️⬇️ dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants