Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependabot warnings about package #86

Open
altano opened this issue Apr 1, 2024 · 0 comments
Open

dependabot warnings about package #86

altano opened this issue Apr 1, 2024 · 0 comments

Comments

@altano
Copy link

altano commented Apr 1, 2024

We don't need to get into a conversation about whether warnings like this are helpful or not, but they are happening.

My latest one was from pulling in eslint-plugin-package-json, because of this dependency chain:

eslint-plugin-package-json 0.12.0
└─┬ package-json-validator 0.6.3
  └─┬ optimist 0.6.1
    └── minimist 0.0.10

It looks like package-json-validator would benefit from either moving from optimist (deprecated) to directly using an updated version of minimist or switching to something like yargs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant