Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: bump @semantic-release/commit-analyzer to 9.0.2 #2258

Merged
merged 1 commit into from Nov 24, 2021

Conversation

AlexanderBabel
Copy link
Contributor

This PR fixes CVE-2021-23425 which was just fixed in the downstream project semantic-release/commit-analyzer#289.

@travi could you please review this PR as well?

@travi
Copy link
Member

travi commented Nov 23, 2021

keep in mind that these issues have been resolvable all along by updating lockfiles since this only changes the lower end of the defined semver ranges. i'm supportive of updating in order to more strongly encourage updating within the earlier ranges, but these should not have been blocking problems

@travi travi merged commit 7f971f3 into semantic-release:master Nov 24, 2021
@github-actions
Copy link

🎉 This PR is included in version 18.0.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants