Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Last commit failed on main and micromatch was not updated #124

Open
carlosjgp opened this issue Oct 7, 2024 · 3 comments
Open

Last commit failed on main and micromatch was not updated #124

carlosjgp opened this issue Oct 7, 2024 · 3 comments

Comments

@carlosjgp
Copy link

https://app.circleci.com/jobs/github/juliuscc/semantic-release-slack-bot/520

34e721a

@MikelArnaiz
Copy link

+1 keeping micromatch at version "4.0.2" it's a security vulnerability
#123

@gazpachu
Copy link

gazpachu commented Nov 8, 2024

@juliuscc @tripodsan I understand you might be busy with other things, but the semantic-release community needs to move forward. This issue has been around since June. Are you still committed to maintaining this repository? if not, would you be willing to transfer the ownership to someone else with time to fix it? Thanks

@arnaudbesnier
Copy link
Contributor

arnaudbesnier commented Nov 21, 2024

In the meantime, this is the workaround we decided to apply to all the repositories of our organization:

"resolutions": {
   "semantic-release-slack-bot/**/micromatch": "^4.0.8"
},

We are using Yarn. 🧶
Using NPM, overrides is probably the way to go.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants