Bump minimatch from 3.0.4 to 3.1.2#180
Bump minimatch from 3.0.4 to 3.1.2#180AndyBitz merged 1 commit intovercel:masterfrom kachkaev:bump-minimatch
Conversation
|
This also closes #165 Maintainers, is it possible to instead use caret ranges, e.g. That way, if there is a security vulnerability in this package (or in |
|
As far as I understand, Vercel folks prefer pinning dependencies in their products. Here is Next.js, for example: This way they save their users from accidental upstream breaking changes within a semver range. Not sure this approach can be revisited easily, so I doubt we’ll be able to introduce |
|
I need to merge this PR. |
|
@vercel, can you give this PR some attention? 🥺 |
AndyBitz
left a comment
There was a problem hiding this comment.
Thank you for opening the issue and providing a PR 🥇
Closes #179