Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bump minimist from 1.2.5 to 1.2.6 #14382

Merged
merged 2 commits into from
Mar 23, 2022

Conversation

fargito
Copy link
Contributor

@fargito fargito commented Mar 22, 2022

Q                       A
Fixed Issues?
Patch: Bug Fix?
Major: Breaking Change? No
Minor: New Feature? No
Tests Added + Pass? No
Documentation PR Link No
Any Dependency Changes? Yes
License MIT

Hello and thanks for your time!

A security issue has been created for minimist@1.2.5, I believe that 1.2.6 fixes it, so I bumped the depenedency.

Also check out the documentation in minimist: https://github.com/substack/minimist#security

Also json5 removed its minimist dependency, so I also updated the dependency

Thanks a lot!

Copy link
Contributor

@JLHwung JLHwung left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@babel-bot
Copy link
Collaborator

babel-bot commented Mar 22, 2022

Build successful! You can test your changes in the REPL here: https://babeljs.io/repl/build/51544/

@fargito
Copy link
Contributor Author

fargito commented Mar 22, 2022

@JLHwung I also bumped json5 which removed its dependency to minimist

@fargito
Copy link
Contributor Author

fargito commented Mar 23, 2022

@existentialism @JLHwung the tests fail on Windows, but it is already the same on main, is it an issue that I need to fix?

@existentialism
Copy link
Member

@fargito reran it, you're good!

@JLHwung JLHwung merged commit ba13e48 into babel:main Mar 23, 2022
@fargito fargito deleted the chore/bump-minimist branch March 23, 2022 18:03
@github-actions github-actions bot added the outdated A closed issue/PR that is archived due to age. Recommended to make a new issue label Jun 23, 2022
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jun 23, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
outdated A closed issue/PR that is archived due to age. Recommended to make a new issue PR: Dependency ⬆️
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants