devpunks / snuggsi

snuggsi ツ - Easy Custom Elements in ~1kB
https://snuggsi.com
MIT License
395 stars 17 forks source link

Fix npm Vulnerabilities #216

Open snuggs opened 3 years ago

snuggs commented 3 years ago

Fixes #215

Notes

Would prefer to upgrade to `npm@7.3 but seems to be breaking changes and introduces 10 more manual vulnerability reviews.

vercel[bot] commented 3 years ago

This pull request is being automatically deployed with Vercel (learn more).
To see the status of your deployment, click below or on the icon next to each commit.

🔍 Inspect: https://vercel.com/sneakyhead/snuggsi/2xd1u9gjd
✅ Preview: https://snuggsi-git-issues-215-fix-vulnerabilities.sneakyhead.vercel.app

snuggs commented 3 years ago

@brandondees @JoshuaBehrens whoops on the re-review request. Was trying out some features.

That said. Check this out. The "AHA" moment is happening! It's always been there as we know. but what's different about this year is the amount of confirming comments. Few years ago when we started the tone was "yeah right. INSTALL ALL THE THINGS". Now..... "Somebody help me". >>>

https://css-tricks.com/npm-ruin-dev/ read the comments

npm ruin dev "Plain 'ol HTML, CSS, & Javascript" 👀 Sound familiar 😉

Seems like "Boring by default" is that (old) new wave 😎

/cc @rianby64 @tmornini @cristhiandick @VicenteRD @btakita @foreverc9 @kurtcagle @janz93 ☝🏽

snuggs commented 3 years ago

@brandondees @JoshuaBehrens we got movement! #SqueakyWheel 🚗

brandondees commented 3 years ago

@snuggs looks like the fix on browsersync is to update its subdependencies more explicitly or do a re-install so that they get bumped up