Thinkmill / manypkg

☔️ An umbrella for your monorepo
MIT License
865 stars 48 forks source link

Dependabot Security Alert: Indirect Dependency "got" needs an update (direct-dep: "package-json" needs update) #180

Closed fbartho closed 7 months ago

fbartho commented 1 year ago

Dependabot reported in one of my repos:

@manypkg/cli@0.20.0 requires got@^9.6.0 via package-json@6.5.0

Indeed, main for manypkg/cli does actually require package-json@6.5.0

And package-json has a later version available that has a newer version of "got"

Any objections if we update it?