ds300 / patch-package

Fix broken node modules instantly 🏃🏽‍♀️💨
MIT License
10.48k stars 295 forks source link

Bump Semver to 7.x #466

Closed stianjensen closed 1 year ago

stianjensen commented 1 year ago

https://github.com/npm/node-semver/blob/main/CHANGELOG.md

Major version change is mainly dropping old node versions.

greefhorst commented 1 year ago

@ds300 @stianjensen is there any progress on this issue? I woke up this morning with a vulnerability report for semver 5.6 in my mailbox, it should be updated to 7.5.2

see https://github.com/advisories/GHSA-c2qf-rxjj-qqgw

jayarjo commented 1 year ago

Please merge this.

orta commented 1 year ago

Given this package declares itself to be node 14+, I don't think this change counts as needing a major semver from this PR ( it indicates that the versions dropped are so old that they can now use let ) - I'll get this merged and it can go out with the next release

s100 commented 1 year ago

@orta Thank you for merging this PR! Could you now publish a new version of patch-package which has this fix in it?

cheesehary commented 1 year ago

@orta Is there an ETA on the next release?

GraceDmello commented 1 year ago

@orta Can we please release a new version of the package?

orta commented 1 year ago

I don't have npm access I'm afraid

ds300 commented 1 year ago

sorry folks I'll do a release now

On Tue, Jul 11, 2023 at 8:47 AM Orta Therox @.***> wrote:

I don't have npm access I'm afraid

— Reply to this email directly, view it on GitHub https://github.com/ds300/patch-package/pull/466#issuecomment-1630322355, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAJPLKIMNL6A7XXERBGG4HTXPUAJPANCNFSM6AAAAAAXM4YS3M . You are receiving this because you were mentioned.Message ID: @.***>

ds300 commented 1 year ago

this jest went out in v7.0.1