Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update dependencies to fix vulnerability #73

Merged
merged 1 commit into from
Jul 1, 2019
Merged

Conversation

tomap
Copy link
Contributor

@tomap tomap commented Jun 12, 2019

No description provided.

@coveralls
Copy link

Coverage Status

Coverage increased (+0.4%) to 86.415% when pulling 048ca22 on tomap:fix/sec into bd7b64b on hexojs:master.

1 similar comment
@coveralls
Copy link

Coverage Status

Coverage increased (+0.4%) to 86.415% when pulling 048ca22 on tomap:fix/sec into bd7b64b on hexojs:master.

@tomap
Copy link
Contributor Author

tomap commented Jun 25, 2019

@hexojs/core see security vulnerabilities by gihub :)

@curbengh
Copy link
Contributor

curbengh commented Jun 26, 2019

they are all minor updates and covered by caret. I think removing package-lock would achieve the same thing?

Another issue with package-lock is every maintenance release of deps also changes the file, makes it not easy to maintain. The main hexo doesn't have it.

Edit: I just aware of hexojs/hexo#3370.

@tomap tomap merged commit 488f3bf into hexojs:master Jul 1, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants