Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Updates for PNPM #7434

Closed
1 task done
deivid-rodriguez opened this issue Jun 14, 2023 · 1 comment
Closed
1 task done

Security Updates for PNPM #7434

deivid-rodriguez opened this issue Jun 14, 2023 · 1 comment
Labels
F: security-updates 🔐 Issues specific to security updates L: javascript:pnpm npm packages via pnpm T: feature-request Requests for new features

Comments

@deivid-rodriguez
Copy link
Contributor

Is there an existing issue for this?

  • I have searched the existing issues

Feature description

We have shipped support for PNPM version updates recently. However, we are still missing the proper logic to implement security update support.

In particular, we need to implement the proper logic to be able to propose updates to the minimum fixed version, given a security advisory.

In addition to that, some other internal changes will be needed to enable this feature, but this issue tracks the changes related to the update logic.

For reference, here is a previous PR implementing the same kind of thing for Github Actions.

@deivid-rodriguez
Copy link
Contributor Author

Dependabot alerts and Security Updates to try and fix them have now been enabled for PNPM 🎉

So let me close this ticket now. Feel free to report any issues you find separately.

Thanks!

@github-project-automation github-project-automation bot moved this from Untriaged to Done in Dependabot Aug 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
F: security-updates 🔐 Issues specific to security updates L: javascript:pnpm npm packages via pnpm T: feature-request Requests for new features
Projects
Archived in project
Development

No branches or pull requests

1 participant