Skip to content

dependabot alerts#296

Merged
mofojed merged 4 commits intodeephaven:mainfrom
mofojed:dependabot-alerts
Nov 16, 2021
Merged

dependabot alerts#296
mofojed merged 4 commits intodeephaven:mainfrom
mofojed:dependabot-alerts

Conversation

@mofojed
Copy link
Member

@mofojed mofojed commented Nov 15, 2021

  • Run npm audit fix in root
  • Run ./node_modules/.bin/lerna exec npm install -- --package-lock-only

@mofojed mofojed added this to the November 2021 milestone Nov 15, 2021
@mofojed mofojed requested a review from vbabich November 15, 2021 22:55
@mofojed mofojed self-assigned this Nov 15, 2021
@vbabich
Copy link
Collaborator

vbabich commented Nov 15, 2021

I'm getting changes in packages/jsapi-shim/package-lock.json and packages/log/package-lock.json when I run npm run clean; npm i. Is this something with my local config?

@mofojed
Copy link
Member Author

mofojed commented Nov 16, 2021

@vbabich No, it wasn't just your local config... it looks like running the package-lock-only command changes the package locks, but then doing a clean install changes it back. I think it's more correct doing the clean/install, as that's what devs are going to do.

@mofojed mofojed merged commit 045d7f1 into deephaven:main Nov 16, 2021
@mofojed mofojed deleted the dependabot-alerts branch November 16, 2021 19:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants