Skip to content

Address Platforms/emscripten/browser_test/package-lock.json Dependabot alerts #158395

Description

@ezio-melotti

Dependabot is currently reporting a few vulnerabilities in Platforms/emscripten/browser_test/package-lock.json.
These alerts are separate from the regular updates listed in dependabot.yml.

There are 5 solutions to this problem:

  1. manually update those deps and fix the alerts;
  2. manually ask dependabot to create security updates for each alert (like 1);
  3. manually dismiss the alert;
  4. configure Dependabot to check and create PRs to update the deps in package-lock.json;
  5. configure Dependabot to ignore package-lock.json (if possible);

If we decide to go with 1/2/3, we would need to manually intervene for any future alert, so 4/5 are better solutions in the long term. If we go with 4/5 it should be enough to list the main branch in dependabot.yml since Dependabot only looks at the main branch.

@hoodmane, do you have any preference?

Footnotes

  1. https://github.com/python/cpython/pull/158394 ↩

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.16new features, bugs and security fixesinfraCI, GitHub Actions, buildbots, Dependabot, etc.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions