Merged
Conversation
af9684c to
a00689b
Compare
lukekarrys
suggested changes
Feb 7, 2023
Contributor
lukekarrys
left a comment
There was a problem hiding this comment.
The changed files in workspaces/arborist/test/fixtures/ were moved in 4c5bd6e and probably got re-added in this PR. Can those be removed?
This is a total rebuild of the package-lock. The diff of the package-lock was audited line by line and changes were assessed. In all but one case the only changes were semver-compatible bumps of subdependencies, and a shuffling of the hoisting of some dev dependencies (which don't affect the published package). The only package that had to be manually re-hoisted was `normalize-package-data`. This was done by installing then uninstalling the version we wanted hoisted (in this case it was semver major version 5).
a00689b to
484c606
Compare
lukekarrys
approved these changes
Feb 7, 2023
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is a total rebuild of the package-lock. The diff of the
package-lock was audited line by line and changes were assessed. In all
but one case the only changes were semver-compatible bumps of
subdependencies, and a shuffling of the hoisting of some dev
dependencies (which don't affect the published package).
The only package that had to be manually re-hoisted was
normalize-package-data. This was done by installing then uninstallingthe version we wanted hoisted (in this case it was semver major version
5).