hold dependency updates back for 7 days #4394
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR will...
Hold dependency updates back for 7 days to reduce the risk of a hacked package version being merged in, because hopefully someone would notice in 7 days and have the hacked version removed.
Also enable
vulnerabilityAlerts
meaning if GitHub mark a version as venerable and have a fix, that is automatically created immediately.Luckily we missed GHSA-pjwm-rvh2-c87w this time, but this should help make things like this less likely to effect us.
Why is this Pull Request needed?
Helps reduce the risk of a hacked package getting merged in, whilst still keeping dependencies up to date and notifying us of any build problems with new versions.