Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
My task is to lower the number of security alerts on repositories I work with.
For many of these dependable issues is trouble that we (I) cannot update the dependency directly as
a) There is currently no new version - e.g., gts is stuck at version without the support of new eslint/prettier, jest test works for last ~2 years on a new version
30.x
but until released (with all backward incompatibilities) there is still two years old version 29.7.0 without updates.b) We cannot update the version due to the backward incompatibility (e.g. solana/web3.js 1.x vs 2.x)
My consideration is to fix it by forcing the (mostly) minor updates in the pnpm lock file - on those dependencies that dependabot requires.
I will be happy to hear opinion on this way of fixing the thingy.