Skip to content

Reminder for npm audit fix #202

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open

Reminder for npm audit fix #202

wants to merge 1 commit into from

Conversation

Yang-33
Copy link
Contributor

@Yang-33 Yang-33 commented Aug 5, 2025

Most npm package alerts can be fixed automatically with npm audit fix --force (it is not perfect, so some manual work is still required).
Because we cannot use a GitHub App token, a reminder should be enough. Automatically creating PRs would be pointless, because the CI jobs will not run, and it may be old(=merging may not resolve all issues)

For now, let's create a reminder as an issue. We review issues regularly, so this should be sufficient.

same as line/line-bot-sdk-nodejs#1357

@Yang-33 Yang-33 requested review from a team and removed request for a team August 5, 2025 09:15
@Yang-33 Yang-33 marked this pull request as draft August 5, 2025 09:15
@Yang-33 Yang-33 force-pushed the reminder-for-npm-audit branch from 9f80fa7 to 313fcdc Compare August 5, 2025 09:22
@Yang-33 Yang-33 marked this pull request as ready for review August 5, 2025 10:04
@Yang-33 Yang-33 requested a review from a team August 5, 2025 10:04
Copy link
Contributor

@eucyt eucyt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you 🙇

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants