-
Notifications
You must be signed in to change notification settings - Fork 554
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): pin dependencies #651
Conversation
d1ae14d
to
768e4a6
Compare
c381515
to
b8d09a6
Compare
4a77588
to
a72d224
Compare
Why do we want this? 🤔 Isn't the |
a72d224
to
151b5ea
Compare
89c9cd4
to
ad8043d
Compare
ad8043d
to
c04efe1
Compare
Codecov Report
|
@LinusU I think this just enforces pinned dependency versions... This would prevent security breach issues like the one that happened a couple years back with event-stream by preventing users from upgrading a dependency to a newer (and possibly malicious) version. The |
f1760ce
to
913c1a1
Compare
b0b4e6b
to
b1815b2
Compare
cb15021
to
c85dbd4
Compare
c85dbd4
to
8dd2525
Compare
🎉 This PR is included in version 4.2.2 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This PR contains the following updates:
^4.1.2
->4.1.2
^2.0.4
->2.0.4
^2.0.0
->2.0.0
^1.18.0
->1.18.0
^1.1.7
->1.1.7
^2.1.0
->2.1.0
^6.3.4
->6.3.4
📌 Important: Renovate will wait until you have merged this Pin PR before creating any upgrade PRs for the affected packages. Add the preset
:preserveSemverRanges
to your config if you instead don't wish to pin dependencies.Renovate configuration
📅 Schedule: At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻️ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by WhiteSource Renovate. View repository job log here.