Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

test: only surface production dependencies, not dev dependencies #5304

Merged
merged 1 commit into from
Dec 17, 2021

Conversation

nicks
Copy link
Member

@nicks nicks commented Dec 17, 2021

Hello @nicks,

Please review the following commits I made in branch nicks/dependabot:

cd8a42a (2021-12-17 14:13:35 -0500)
test: only surface production dependencies, not dev dependencies
I have no idea why this isn't the default, here are some threads on the issues:
dependabot/dependabot-core#4146
dependabot/dependabot-core#2521
facebook/create-react-app#11174

Code review reminders, by giving a LGTM you attest that:

  • Commits are adequately tested
  • Code is easy to understand and conforms to style guides
  • Incomplete code is marked with TODOs
  • Code is suitably instrumented with logging and metrics

…endency vulnerabilities

I have no idea why this isn't the default, here are some threads on the issues:
dependabot/dependabot-core#4146
dependabot/dependabot-core#2521
facebook/create-react-app#11174
@nicks nicks merged commit 25fc4b6 into master Dec 17, 2021
@nicks nicks deleted the nicks/dependabot branch December 17, 2021 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant