Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot Security warning for this package. #11

Open
ottovw opened this issue Jan 24, 2021 · 6 comments
Open

Dependabot Security warning for this package. #11

ottovw opened this issue Jan 24, 2021 · 6 comments
Labels
dependencies Pull requests that update a dependency file enhancement New feature or request good first issue Good for newcomers

Comments

@ottovw
Copy link

ottovw commented Jan 24, 2021

Dependabot is triggering a warning because of this package. Please update Dependencies.

(You can activate Dependabot in the Github settings for free for your repo)

Thanks

Dependabot cannot update node-notifier to a non-vulnerable version
The latest possible version that can be installed is 6.0.0 because of the following conflicting dependency:

[email protected] requires node-notifier@^6.0.0 via a transitive dependency on @jest/[email protected]
The earliest fixed version is 8.0.1.
stegano added a commit that referenced this issue Jan 27, 2021
@stegano
Copy link
Owner

stegano commented Jan 27, 2021

Hi @ottovw

Thanks for your opinion, I just fixed package dependencies
This version will be released on npm soon.

Thanks! 😀

@stegano stegano added dependencies Pull requests that update a dependency file enhancement New feature or request good first issue Good for newcomers labels Jan 27, 2021
Repository owner deleted a comment from allcontributors bot Jan 27, 2021
Repository owner deleted a comment from allcontributors bot Jan 27, 2021
@stegano
Copy link
Owner

stegano commented Jan 27, 2021

@all-contributors please add @ottovw for security

@allcontributors
Copy link
Contributor

@stegano

This project's configuration file has malformed JSON: .all-contributorsrc. Error:: Unexpected token } in JSON at position 576

@stegano
Copy link
Owner

stegano commented Jan 27, 2021

Sorry to keep mentioning.. 😭

@all-contributors please add @ottovw for security

@allcontributors
Copy link
Contributor

@stegano

I've put up a pull request to add @ottovw! 🎉

@ottovw
Copy link
Author

ottovw commented Jan 30, 2021

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file enhancement New feature or request good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

2 participants