Skip to content

Conversation

@bpedersen2
Copy link
Contributor

@bpedersen2 bpedersen2 commented Dec 5, 2025

This ensures we have most non-breaking security fixes in package-lock.json.

@bpedersen2 bpedersen2 requested a review from a team as a code owner December 5, 2025 07:36
This ensures we have most non-breaking security fixes in
package-lock.json.

Change-Id: Ie2e485a05784d118d434bb92e33906b10b73da5d
Copy link
Member

@nitrosx nitrosx left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@bpedersen2: I am wondering if we need to commit the package-lock.json to the repo or we should advice the users to to run an update with npm?

@nitrosx
Copy link
Member

nitrosx commented Dec 5, 2025

I forget to say that I trust your judgment and my comment is not blocking if you say that we need this PR.
Thanks for your hard work

@fpotier
Copy link
Member

fpotier commented Dec 5, 2025

@bpedersen2: I am wondering if we need to commit the package-lock.json to the repo or we should advice the users to to run an update with npm?

the lock file is intended to be comitted

@sbliven
Copy link
Member

sbliven commented Dec 5, 2025

It's good to run this regularly. I'm surprised that dependabot didn't update these automatically.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants