Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: bump conventional commits parser to version 3.2.3 #293

Merged
merged 2 commits into from
Nov 24, 2021

Conversation

AlexanderBabel
Copy link
Contributor

This PR fixes CVE-2021-23425.

@travi Unfortunately, I did not see that this project also uses this package. This means the upstream semantic-release needs to be updated one more time.

@travi
Copy link
Member

travi commented Nov 24, 2021

This means the upstream semantic-release needs to be updated one more time.

as i mentioned in the other thread, i'm in favor of raising the minimum end of the range in cases like this, but updating a project's lockfile to use the newer version, still in-range, would also solve the mentioned CVE. is there part of the bigger picture that i am overlooking that is preventing updates that makes you suggest that this is a need?

@travi travi enabled auto-merge (squash) November 24, 2021 16:14
@travi travi merged commit 5f9d65d into semantic-release:master Nov 24, 2021
@github-actions
Copy link

🎉 This PR is included in version 10.0.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants