-
-
Notifications
You must be signed in to change notification settings - Fork 3.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update package-lock.json #384
Comments
I assume that GitHub is complaining about one of our dependencies or sub-dependencies, but I can't see which one since this feature is limited to repo admins by default: https://help.github.com/articles/about-security-alerts-for-vulnerable-dependencies/ I usually use this tool to update dependencies: https://github.com/tjunnone/npm-check-updates |
Yea, for some reason the comment cut off a line: "The marked dependency defined in package-lock.json has a known moderate severity security vulnerability in version range < 0.3.9 and should be updated. Review vulnerable dependency" Hah. I'll try that myself tomorrow or something but I'll probably break it 😂 |
See #387. Here's what I did:
|
Yo @nylen you able to grab this and walk me through a how-to for similar?
https://github.com/remoteintech/remote-jobs/blob/3bbfe49a51f7765b07aaf489580f731196e75cf1/package-lock.json
Cheers!
The text was updated successfully, but these errors were encountered: