-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: update semantic-release version #25
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It will break what could be broken.
Any ideas of how can we further test this without breaking every single repo in the organization? |
Branch and release in different channel semantic-prerelease@break, but before that heavy local testing, for major packages in various suites. |
The latest commit adds dependencies which were present in The |
Migration to the latest semantic release version is a noble idea, but it would take a deep look into how their plugin system works now. The CVE has no impact on customers whatsoever, as it only concerns build logs which are private to us. |
@tsvetomir Do you suggest ignoring the warning for now? I'm totally OK with this, but wanted to start out a discussion, even if a PR was not the best place for it. |
Closing, ad it's not possible to override the major version from a plugin in the latest semantic-release versions. |
We have recently received a security-vulnerability notification from
dependabot
in thekendo-react-private
repository, about CVE-2020-26226. Due to the way dependabot works (checks for vulnerabilities after a commit), we would be seeing the notification in other repositories soon.Updating the package to version
17.2.3
would be enough for patching the vulnerability and should not require any changes from our side (at least from my local testing). Updating tolatest
(18) would require us to bump thenode
version ot>14
which I'm afraid is not possible at the moment.