Upgrades various developer dependencies to silence dependabot. #446
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
All of these "vulnerabilities" exist only on developer dependencies (package.json's
devDependencies
list) and as such should not be treated with the same level of severity as their dependabot entries imply. However, they're obviously still worth updating. Further work will be done on updating the other vulnerable dependencies.It updates the following packages:
via dependabot, and:
manually, which should close some of the other "sub-dependent" vulnerabilities that could not be auto-updated.