amplitude / Amplitude-JavaScript

JavaScript SDK for Amplitude
MIT License
315 stars 132 forks source link

chore: bump versions to remediate critical and high Dependabot vulns #583

Closed falconandy closed 1 year ago

falconandy commented 1 year ago

Summary

Bump versions to remediate critical and high Dependabot vulns

Before: 17 dependabot alers After: 6 alerts = 3 high + 2 moderate + 1 low

The 3 high-level alerts can't be resolved now: packages karma-sauce-launcher, @docusaurus/core and @docusaurus/preset-classic should be updated by their authors.

Unsupported packages are replaced: watch -> chokidar-cli, rollup-plugin-uglify -> @rollup/plugin-terser

Checklist