chore(payments): add npm auditing to payments-server dependencies #1896
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Separated into two commits: one readable commit, and one with package-lock.json noise.
First commit: following the advice in the "enable security scanning of 3rd-party libraries and dependencies" checkbox in issue #1128, adds npm dependency auditing to the payments-server npm lint scripts as
npm lint:deps
. Theaudit-filter
package requires an.npmrc
file with a specific JSON format, so added that, too.The second commit contains package-lock.json changes created by
audit-filter
automatically updating stale dependencies to eliminate known nsp errors.