Dependabot is currently reporting a few vulnerabilities in Platforms/emscripten/browser_test/package-lock.json.
These alerts are separate from the regular updates listed in dependabot.yml.
There are 5 solutions to this problem:
- manually update those deps and fix the alerts;
- manually ask dependabot to create security updates for each alert (like 1);
- manually dismiss the alert;
- configure Dependabot to check and create PRs to update the deps in
package-lock.json;
- configure Dependabot to ignore
package-lock.json (if possible);
If we decide to go with 1/2/3, we would need to manually intervene for any future alert, so 4/5 are better solutions in the long term. If we go with 4/5 it should be enough to list the main branch in dependabot.yml since Dependabot only looks at the main branch.
@hoodmane, do you have any preference?
Dependabot is currently reporting a few vulnerabilities in
Platforms/emscripten/browser_test/package-lock.json.These alerts are separate from the regular updates listed in
dependabot.yml.There are 5 solutions to this problem:
package-lock.json;package-lock.json(if possible);If we decide to go with 1/2/3, we would need to manually intervene for any future alert, so 4/5 are better solutions in the long term. If we go with 4/5 it should be enough to list the
mainbranch independabot.ymlsince Dependabot only looks at themainbranch.@hoodmane, do you have any preference?
Footnotes
https://github.com/python/cpython/pull/158394 ↩