-
Notifications
You must be signed in to change notification settings - Fork 561
chore(deps): pin dependencies #651
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
d1ae14d to
768e4a6
Compare
c381515 to
b8d09a6
Compare
4a77588 to
a72d224
Compare
|
Why do we want this? 🤔 Isn't the |
a72d224 to
151b5ea
Compare
89c9cd4 to
ad8043d
Compare
ad8043d to
c04efe1
Compare
Codecov Report
|
|
@LinusU I think this just enforces pinned dependency versions... This would prevent security breach issues like the one that happened a couple years back with event-stream by preventing users from upgrading a dependency to a newer (and possibly malicious) version. The |
f1760ce to
913c1a1
Compare
b0b4e6b to
b1815b2
Compare
cb15021 to
c85dbd4
Compare
c85dbd4 to
8dd2525
Compare
|
🎉 This PR is included in version 4.2.2 🎉 The release is available on: Your semantic-release bot 📦🚀 |
This PR contains the following updates:
^4.1.2->4.1.2^2.0.4->2.0.4^2.0.0->2.0.0^1.18.0->1.18.0^1.1.7->1.1.7^2.1.0->2.1.0^6.3.4->6.3.4📌 Important: Renovate will wait until you have merged this Pin PR before creating any upgrade PRs for the affected packages. Add the preset
:preserveSemverRangesto your config if you instead don't wish to pin dependencies.Renovate configuration
📅 Schedule: At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻️ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by WhiteSource Renovate. View repository job log here.