Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
hold dependency updates back for 7 days (video-dev#4394)
* hold dependency updates back for 7 days to reduce the risk of a hacked package version being merged in, because hopefully someone would notice in 7 days and have the hacked version removed. Also enable `vulnerabilityAlerts` meaning if GitHub mark a version as venerable and have a fix, that is automatically created immediately. * disable lock file maintenance because it would update a transitive dependency early
- Loading branch information