-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Upgrade yarn version #1211
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Upgrade yarn version #1211
Conversation
Since we're not in a hurry most of the time, I think it's ok to use "7d", it should be enough to prevent most of the supply chain attacks. And use npmPreapprovedPackages for |
We also have to think about the opposite side of this. When you want to update to a safer version currently released (nextjs / react recently). I guess you just need to add temporarily to Also, for our |
I think yes, I don't see other solutions
Yes, wanted to say it too but forgot |
|
Hey guys thanks for the discussion! So been researching as well, and I think:
yeah I dont see a better solution either, but for now I have added (our maintainer packages + react, next patch versions) since those are main ones. We can can also think of allowing (hardhat patch version) their. And for some excpetional cases we follow the flow of adding packages on-demand and then removing them.
Ohh yes! We shall add them 🙌 |
|
I think we need to remove react/next from preapproved packages. For last react/next CVE's it works (when patch versions added the fixes), but probably it's better to update them that way just in case?
|
Ohh man :( I seee yup and agree, the more I think and read it just makes sense to only have our packages (which are controled by us) to have in |
Kushmanmb
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yarn install
|
This is ready to be merged I feel 🙌 |
rin-st
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Lgtm, thanks!
Description
Ran:
The #1184 seems way too old. Also, I'm not sure what commands they used to migrate because there are some files that need to be added which were not present.
TODO:
Research about
npmMinimalAgeGateand see whats the best and standard people are using and add it