Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump semver #1771

Merged
merged 1 commit into from
Jul 12, 2023
Merged

Bump semver #1771

merged 1 commit into from
Jul 12, 2023

Conversation

henrymercer
Copy link
Contributor

Bumps semver to fixed versions (see GHSA-c2qf-rxjj-qqgw). Use overrides to address dependencies on semver that come from packages that haven't been updated yet. This is a precaution as the attack vector here (ReDoS) is likely not relevant to the Action.

Merge / deployment checklist

  • Confirm this change is backwards compatible with existing workflows.
  • Confirm the readme has been updated if necessary.
  • Confirm the changelog has been updated if necessary.

@henrymercer henrymercer requested a review from a team as a code owner July 11, 2023 19:52
Copy link
Contributor

@aeisenberg aeisenberg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deleting 16k lines is not bad either.

@henrymercer henrymercer merged commit 12aa0a6 into main Jul 12, 2023
@henrymercer henrymercer deleted the henrymercer/update-semver branch July 12, 2023 09:52
@github-actions github-actions bot mentioned this pull request Jul 14, 2023
6 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants