Skip to content

Update tmp package to the latest version#2730

Merged
adamziel merged 2 commits intoWordPress:trunkfrom
wojtekn:update/tmp-package-to-the-latest-version
Oct 8, 2025
Merged

Update tmp package to the latest version#2730
adamziel merged 2 commits intoWordPress:trunkfrom
wojtekn:update/tmp-package-to-the-latest-version

Conversation

@wojtekn
Copy link
Collaborator

@wojtekn wojtekn commented Oct 7, 2025

Motivation for the change, related issues

I want to close Dependabot finding: https://github.com/Automattic/studio/security/dependabot/57

Implementation details

Testing Instructions (or ideally a Blueprint)

Confirm that the build works fine.

@wojtekn wojtekn requested a review from a team as a code owner October 7, 2025 12:58
@wojtekn wojtekn self-assigned this Oct 7, 2025
@wojtekn wojtekn requested a review from adamziel October 7, 2025 13:10
@adamziel
Copy link
Collaborator

adamziel commented Oct 7, 2025

Thanks @wojtekn! Would peerDependencies also work for this? I worry about someone removing the tmp from dependencies once they realize nothing imports it directly

@adamziel adamziel added the [Type] Enhancement New feature or request label Oct 7, 2025
@wojtekn
Copy link
Collaborator Author

wojtekn commented Oct 8, 2025

As far as I read, peerDependencies wouldn't work - they don't force updates of transitive dependencies, only declare that a dependency should be available.

I added direct dependency and kept override to:

  • make it explicit, so it won't be accidentally removed
  • force all instances to use 0.2.5, including deep deps

Let me know what you think.

@wojtekn wojtekn force-pushed the update/tmp-package-to-the-latest-version branch from a902ab1 to 0cc26b9 Compare October 8, 2025 07:10
@adamziel
Copy link
Collaborator

adamziel commented Oct 8, 2025

TIL, thank you!

@adamziel adamziel merged commit 6ccd339 into WordPress:trunk Oct 8, 2025
27 of 28 checks passed
@wojtekn wojtekn deleted the update/tmp-package-to-the-latest-version branch October 29, 2025 11:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

[Type] Enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants