Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump nanoid from 3.1.20 to 3.2.0. #1342

Merged
merged 1 commit into from Jan 28, 2022
Merged

Bump nanoid from 3.1.20 to 3.2.0. #1342

merged 1 commit into from Jan 28, 2022

Conversation

dcr-stripe
Copy link
Contributor

@dcr-stripe dcr-stripe commented Jan 28, 2022

r? @richardm-stripe

Summary

Bump nanoid from 3.1.20 to 3.2.0. I had to pin it via resolutions due to our Mocha dep. Unfortunately this dependency was only changed in Mocha 9+, which we can't currently update to as it no longer supports Node 10 (https://github.com/mochajs/mocha/blob/master/CHANGELOG.md#boom-breaking-changes).

Motivation

CVE-2021-23566

@dcr-stripe dcr-stripe merged commit f8005f4 into master Jan 28, 2022
@dcr-stripe dcr-stripe deleted the dcr-update-nano branch January 28, 2022 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants