Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Force update some npm packages which has ReDoS reports #1046

Merged
merged 7 commits into from
Feb 20, 2025

Conversation

kachick
Copy link
Owner

@kachick kachick commented Feb 20, 2025

  • Remove outdated esbuild special config from renovate.json
  • Force apply patched version for @octokit/plugin-paginate-rest
  • Force apply patched version for @octokit/endpoint
  • Force apply patched version for @octokit/request
  • Force apply patched version for @octokit/request-error

GitHub does not reply actions/toolkit#1960 and we should manually bump these by myself

And without this, dependabot internal reports are much noisy. See #998

@kachick kachick merged commit d8d93b0 into main Feb 20, 2025
42 checks passed
@kachick kachick deleted the add-overrides-for-vuls branch February 20, 2025 02:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant