Skip to content

chore: bump closure-calculate-chunks#26

Closed
jrobinson01 wants to merge 3 commits intomasterfrom
bump-closure-calculate-chunks
Closed

chore: bump closure-calculate-chunks#26
jrobinson01 wants to merge 3 commits intomasterfrom
bump-closure-calculate-chunks

Conversation

@jrobinson01
Copy link
Copy Markdown
Contributor

bumps closure-calculate-chunks to fix dependabot warnings for lodash

Copy link
Copy Markdown
Contributor

@barronhagerman barronhagerman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think this will fix any of the open dependabot alerts. Also, was upgrading to Yarn 4 intended? It looks like #25 should fix all of the lodash vulnerabilities.

linkType: hard

"lodash@npm:^4.17.15":
version: 4.17.21
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

https://github.com/Banno/banno-plugin-framework-bridge/security/dependabot/28 says the earliest patched version is 4.18.0, and #25 is already open to do that.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you're right, 25 does look like it would fix it. I didn't see that linked from the dependabot alert: https://github.com/Banno/banno-plugin-framework-bridge/security/dependabot/16 I just saw that it pointed to closure-calculate-chunks as the reason for the dep. I'll get the other PR's merged.

the bump to yarn 4 was intentional. Is there a reason this should stay on yarn 1.x?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wondered why it didn't link to all of the lodash alerts 🤷 I don't know of any reason to keep it at Yarn 1, but I just wanted to check because it wasn't mentioned in the PR body.

@jrobinson01
Copy link
Copy Markdown
Contributor Author

closing as this only bumps the project to yarn 4, closure-calculate-chunks is already at the latest version.

@jrobinson01 jrobinson01 closed this Apr 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants