Skip to content

Update vulnerable packages to latest supported versions#33

Open
amccarthy1 wants to merge 2 commits into
jonschlinkert:masterfrom
amccarthy1:bump-package-versions
Open

Update vulnerable packages to latest supported versions#33
amccarthy1 wants to merge 2 commits into
jonschlinkert:masterfrom
amccarthy1:bump-package-versions

Conversation

@amccarthy1
Copy link
Copy Markdown

@amccarthy1 amccarthy1 commented Nov 11, 2022

Fixes #32
(I hope)

There are many security advisories out for some dependencies of this project. I know it was last updated 8 years ago, but many packages still have this somewhere in their dependency trees, so it's good to fix these updates and keep everybody's code secure.

Notes:

  • I couldn't update globby to latest, as the latest few major versions dropped support for commonjs modules. Other packages were updated to their latest versions (I left devDependencies alone, as I was having trouble getting things to build correctly otherwise)

There is a minor formatting change to the output of this package with this; some of the test files output some tags on a single line instead of multiple lines. Otherwise the tests seem unaffected.

Let me know if there's a better way to test this than running the test suite and I'd be happy to help out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security vulns in dependencies

1 participant