Skip to content

bump stylus-supremacy to 5.0.0 & overrides vulnerabilities#3

Open
adrienWeiss wants to merge 1 commit intoqnp:masterfrom
adrienWeiss:bump-stylus-supremacy
Open

bump stylus-supremacy to 5.0.0 & overrides vulnerabilities#3
adrienWeiss wants to merge 1 commit intoqnp:masterfrom
adrienWeiss:bump-stylus-supremacy

Conversation

@adrienWeiss
Copy link
Contributor

Hello,

stylus-supremacy was recently updated to 5.0.0
I was digging around its dependencies to see if I could get rid of some package overrides but unfortunately it still relies on stylint which is not maintained anymore and parent of vulnerable dependencies.
Still, after playing a bit I figured why not take the opportunity to still update stylus-supremacy on your project and also patch its own declared vulnerabilities.
We still need to have 2 overrides (or resolutions for yarn) though.
I also bumped vitest which was also coming with vulnerabilities.

I know we really shouldn't mind that much about package vulnerabilities but as you may know some of us are dealing with company policies which take no real interest in making sure those represent real danger 😓

Please let me know if you'd rather bump these dependencies a different way.

Again, thanks for this project, really precious for people like me which are still dealing with large codebases in Vue/stylus 🙏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant