Skip to content

Conversation

@Stamo-Gochev
Copy link

@Stamo-Gochev Stamo-Gochev commented Jan 24, 2025

Implements #28

Caution

The changes are NOT tested for various scenarios, so this might be breaking (although the security alerts might be fixed. We need to do further testing. RIght now testing is hard as semantic-release wants to push git tags, publish artifacts, etc. in order for you to test the full pipeline, which is risky. Some changes are also not thoroughly reviewed as the initial idea is to test the hypothesis that all security alerts can be fixed in a consuming package. I tested this in kendo-inputs-common and this seems to work according to the alerts.

TODO

  • consider if the package will move forward with the changes
  • decide whether to release this in a new breaking version - add the necessary commit message in this case
  • evaluate whether to move on with just a develop breaking change version to test in other packages

@Stamo-Gochev Stamo-Gochev changed the title Npm vulnerabilities Update semantic-release to version 24.x Jan 24, 2025
@Stamo-Gochev Stamo-Gochev marked this pull request as draft January 24, 2025 09:38
@tsvetomir
Copy link
Member

The version can't be overridden in the current semantic-release versions due to semantic-release/semantic-release#2641. Closing.

@tsvetomir tsvetomir closed this Mar 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants