Conversation
|
👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎ This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. Ignoring: Next stepsTake a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with |
f5dc2c7 to
3251623
Compare
3251623 to
2385628
Compare
|
@SocketSecurity ignore-all @SocketSecurity ignore npm/methods@1.1.2 |
mcmire
left a comment
There was a problem hiding this comment.
This looks pretty good! I had some minor suggestions on various things I noticed, but I'm pretty happy with this.
I noticed that creating the release branch took more time than expected, but maybe that's how it's always been. Maybe something we can look at in a future PR.
|
Report too large to display inline |
The Release UI Beta
You can test the new feature in
create-release-branchlocally with Core by following these steps:1️⃣ Checkout the Feature Branch
3️⃣ Run the Command in
create-release-branchyarn && yarn build4️⃣ Update Core’s package.json
4️⃣ Run the Command in Core
yarn && yarn create-release-branch -iFixes: #163