Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

remove npm-upgrade from dependencies #702

Merged
merged 1 commit into from
Mar 4, 2024
Merged

remove npm-upgrade from dependencies #702

merged 1 commit into from
Mar 4, 2024

Conversation

jbr
Copy link
Contributor

@jbr jbr commented Mar 4, 2024

there seem to be a number of vulnerabilities in npm-upgrade's dependencies, and it is unclear if this package is maintained. in order to keep the security tab and npm audit clear, this pr removes this dependency.

I retained the npm upgrade-interactive script, which works just fine if you have npm-upgrade installed globally

@jbr jbr requested a review from a team as a code owner March 4, 2024 19:54
@coveralls
Copy link

Pull Request Test Coverage Report for Build 8146301562

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 84.871%

Totals Coverage Status
Change from base Build 8145847713: 0.0%
Covered Lines: 3451
Relevant Lines: 4079

💛 - Coveralls

@jbr jbr merged commit 5bd9e27 into main Mar 4, 2024
5 checks passed
@jbr jbr deleted the remove-npm-upgrade branch March 4, 2024 20:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants