Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[hotfix] Update dependencies #194

Merged
merged 3 commits into from Apr 26, 2022

Conversation

neogeek
Copy link
Contributor

@neogeek neogeek commented Apr 11, 2022

This is a maintenance PR that takes the package audit from:

11 vulnerabilities (5 moderate, 2 high, 4 critical)

to

2 vulnerabilities (1 high, 1 critical)

by updating the following packages:

  1. mocha 6.2.0 -> 9.2.2
  2. markdown-it 9.0.1 -> 12.3.2
  3. commander 2.20.0 -> 9.1.0

I've also been looking into how to update the jsdoctypeparser package. It is a bit more of a complicated update compared to the packages above, but I think it's doable.

@Twipped Twipped merged commit b05cc33 into tj:master Apr 26, 2022
@Twipped
Copy link
Collaborator

Twipped commented Apr 26, 2022

Thank you for doing the footwork on all this. It's been so long in coming, but I just haven't had the available time and brain space to tackle it.

I actually just came back around to this project today after getting pissed at jsdoc-to-markdown being so bad at its job. Might be time for a refresh.

@neogeek
Copy link
Contributor Author

neogeek commented Apr 26, 2022

Of course! I'm happy to help out.

@neogeek neogeek deleted the hotfix/update-dependencies branch April 26, 2022 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants