GabeDuarteM / semantic-release-chrome

Set of semantic-release plugins for publishing a Chrome extension release
https://www.npmjs.com/package/semantic-release-chrome
MIT License
43 stars 16 forks source link

Update to the latest version of chrome-webstore-upload to avoid vulnerability in got package #94

Closed melink14 closed 2 years ago

melink14 commented 2 years ago

Issue

Problem

There's a vulnerability in got (https://github.com/advisories/GHSA-pfrx-2q88-qq97) which can be fixed by targeting a newer version of chrome-webstore-upload.

Suggested solution

I think we could tell renovate to update to 1.0.0; it should not have any breaking changes that affect this package.

github-actions[bot] commented 2 years ago

:tada: This issue has been resolved in version 2.0.0 :tada:

The release is available on:

Your semantic-release bot :package::rocket: