Skip to content

Conversation

@GarboMuffin
Copy link
Member

npm gets compromised every other day. We don't really benefit from updating to every little version of ESLint (etc.) but the risks are distinctly non-zero.

@github-actions github-actions bot added the pr: other Pull requests that neither add new extensions or change existing ones label Nov 25, 2025
@GarboMuffin GarboMuffin added the dependencies Pull requests that update a dependency file label Nov 25, 2025
@GarboMuffin GarboMuffin merged commit 3c0f724 into master Nov 25, 2025
5 checks passed
@GarboMuffin GarboMuffin deleted the dependabot-allowlist branch November 25, 2025 02:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file pr: other Pull requests that neither add new extensions or change existing ones

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants