sdawood / json-tots

JSON Template of Templates
MIT License
9 stars 4 forks source link

fix(security): allow latest minor version for dependencies #27

Closed winstonralph closed 2 years ago

sdawood commented 2 years ago

Hello Winston, I see that you are trying to pump up some minor versions, but I notice that you are also modifying the README to point to another form of the npm package, would you clarify? And maybe open another PR with only the version pumping updates

winstonralph commented 2 years ago

Hi Shaady, Sorry I fixed up the PR with only the version bumps. Basically our security scans were picking up vulnerabilities. The reason why I was forking and creating a new npm package was because I could see there wasn't much activity on this project for quite some time. Many thanks, Winston

On Mon 11 Oct 2021, 16:06 Shaady Dawood, @.***> wrote:

Hello Winston, I see that you are trying to pump up some minor versions, but I notice that you are also modifying the README to point to another form of the npm package, would you clarify? And maybe open another PR with only the version pumping updates

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/sdawood/json-tots/pull/27#issuecomment-940113292, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAQGGII7F7MTL6YZA5UFIGDUGL4OVANCNFSM5FYN2BKA . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.