Thinkmill / manypkg

☔️ An umbrella for your monorepo
MIT License
891 stars 48 forks source link

Bump package-json in CLI package.json from 6.5.0 to 8.1.0 (Vul Fix) #176

Closed MrNekoShin closed 10 months ago

MrNekoShin commented 1 year ago

package-json 6.5.0 used was on an older version of the dependency called 'got' which has this issue "Got allows a redirect to a UNIX socket - https://github.com/advisories/GHSA-pfrx-2q88-qq97"

changeset-bot[bot] commented 1 year ago

⚠️ No Changeset found

Latest commit: 6430cc94c0138a09dc32cbcbc1d4316a9a3febed

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Andarist commented 10 months ago

superseded by https://github.com/Thinkmill/manypkg/pull/181