-
-
Notifications
You must be signed in to change notification settings - Fork 32.8k
Lock file maintenance #46634
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Lock file maintenance #46634
Conversation
Netlify deploy previewhttps://deploy-preview-46634--material-ui.netlify.app/ Bundle size report
|
|
We have a lot of dependencies security alerts in https://github.com/mui/material-ui/security/dependabot vs. https://github.com/mui/mui-x/security/dependabot that has almost none. The only difference I'm aware of between the two repositories is that here we don't merge the "Lock file maintenance" PRs, while they do. Trying this out. |
7506f06 to
b27cf31
Compare
0e70fef to
e45414f
Compare
e45414f to
613bf9a
Compare
613bf9a to
2cce272
Compare
2cce272 to
5d7dd1d
Compare
Ok, it didn't help much, the root seems closer to be about: dependabot/dependabot-core#4364. Most of the alerts are not about the root pnpm-lock.yaml file. I have closed all the ones related to a different manifest file: https://github.com/mui/material-ui/security/dependabot?q=is%3Aopen+-manifest%3Apnpm-lock.yaml+. The rest of the issues https://github.com/mui/material-ui/security/dependabot seems to come from:
|
This PR contains the following updates:
🔧 This Pull Request updates lock files to use the latest dependency versions.
Configuration
📅 Schedule: Branch creation - "before 6:00am on the first day of the month" in timezone UTC, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.