Skip to content

Conversation

@erj826
Copy link
Collaborator

@erj826 erj826 commented Jul 14, 2022

Proposed Changes

In lieu of adding a yarn resolution for parse-url (draft here) to resolve security vulnerabilities we have decided to bump the lowest supported Node version to v14 as it is the current lowest LTS and bump Lerna to v5 (which includes the vulnerability patches).

Types of changes

  • Bugfix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation Update (if none of the other choices apply)

@erj826 erj826 marked this pull request as ready for review July 14, 2022 19:04
@erj826 erj826 changed the title Bump Node SUpport to 14 and Lerna to 5.1.8 Bump Node Support to 14 and Lerna to 5.1.8 Jul 14, 2022
@GaryPWhite
Copy link
Collaborator

just needs a change on this here command to use --immutable instead https://github.com/wayfair/git-parse/blob/main/.github/workflows/pr-checks.yml#L29

@GaryPWhite
Copy link
Collaborator

seems like it uses --frozen-lockfile quite a bit -- will want to find/replace

Copy link
Collaborator

@GaryPWhite GaryPWhite left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ez lgtm!

@erj826 erj826 changed the title Bump Node Support to 14 and Lerna to 5.1.8 Chore: Bump Node Support to 14 and Lerna to 5.1.8 Jul 14, 2022
@erj826 erj826 merged commit d2c091f into wayfair:main Jul 14, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants