Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: migrate to yarn v4 #260

Merged
merged 1 commit into from Dec 6, 2023
Merged

build: migrate to yarn v4 #260

merged 1 commit into from Dec 6, 2023

Conversation

JounQin
Copy link
Collaborator

@JounQin JounQin commented Dec 6, 2023

No description provided.

Copy link

changeset-bot bot commented Dec 6, 2023

⚠️ No Changeset found

Latest commit: 0faa37e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Copy link

New and updated dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
@1stg/lib-config 12.0.0 shell +1224 434 MB jounqin
@pkgr/rollup 4.1.3 eval, shell +177 223 MB jounqin
size-limit-preset-node-lib 0.3.0 environment +33 795 kB jounqin
simple-git-hooks 2.9.0 None +0 12.8 kB toplenboren
@types/is-core-module 2.2.2 None +0 3.06 kB types
eslint-module-utils 2.8.0 filesystem, environment +2 96.5 kB ljharb
@types/is-glob 4.0.4 None +0 3.57 kB types
@changesets/changelog-github 0.5.0 network, environment +11 1.06 MB changesets-release-bot
is-core-module 2.13.1 None +2 72.5 kB ljharb
@commitlint/cli 17.8.1 eval +187 46.2 MB escapedcat
@types/debug 4.1.12 None +1 9.65 kB types
@types/node 18.19.2 None +1 3.9 MB types
react 18.2.0 environment +1 331 kB gnoff
debug 4.3.4 environment +1 49.2 kB qix
get-tsconfig 4.7.2 filesystem +1 116 kB hirokiosame
is-glob 4.0.3 None +1 19.8 kB phated
fast-glob 3.3.2 None +17 505 kB mrmlnc
eslint-plugin-import 2.29.0 eval, filesystem +169 15.9 MB ljharb
enhanced-resolve 5.15.0 environment +2 267 kB thelarkinn
lint-staged 13.3.0 filesystem, environment +55 2.52 MB okonet
@types/unist 2.0.10 None +0 8.56 kB types
prettier 2.8.8 environment +0 11.2 MB prettier-bot
typescript 5.3.2 None +0 32 MB typescript-bot
@mozilla/glean 1.3.0...3.0.0 network +4/-1 1.96 MB dataops-ci-bot
type-coverage 2.25.0...2.27.0 filesystem, environment +28/-0 33.6 MB plantain_00
size-limit 8.2.6...11.0.0 environment +28/-0 682 kB ai
@changesets/cli 2.26.2...2.27.1 None +244/-5 23.4 MB changesets-release-bot
eslint 8.37.0...8.55.0 eval, filesystem +90/-0 10.6 MB eslintbot

Copy link

socket-security bot commented Dec 6, 2023

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: es5-ext@0.10.62

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

@JounQin JounQin force-pushed the build/yarn_v4 branch 4 times, most recently from 6039670 to a8df648 Compare December 6, 2023 15:27
@JounQin
Copy link
Collaborator Author

JounQin commented Dec 6, 2023

@SocketSecurity ignore es5-ext@0.10.62

Copy link

codesandbox-ci bot commented Dec 6, 2023

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

@JounQin JounQin merged commit cecec35 into master Dec 6, 2023
11 of 12 checks passed
@JounQin JounQin deleted the build/yarn_v4 branch December 6, 2023 15:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

None yet

1 participant