Dependabot is currently reporting a few vulnerabilities in Platforms/emscripten/browser_test/package-lock.json.
These alerts are separate from the regular updates listed in dependabot.yml.
There are 5 solutions to this problem:
- manually update those deps and fix the alerts;
- manually ask dependabot to create security updates for each alert (like 1);
- manually dismiss the alert;
- configure Dependabot to check and create PRs to update the deps in
package-lock.json;
- configure Dependabot to ignore
package-lock.json (if possible);
If we decide to go with 1/2/3, we would need to manually intervene for any future alert, so 4/5 are better solutions in the long term. If we go with 4/5 it should be enough to list the main branch in dependabot.yml to solve the alerts since Dependabot only looks at the main branch, unless we want to update deps on maintenance branches and/or keep all branches aligned.
@hoodmane, do you have any preference?
Dependabot is currently reporting a few vulnerabilities in
Platforms/emscripten/browser_test/package-lock.json.These alerts are separate from the regular updates listed in
dependabot.yml.There are 5 solutions to this problem:
package-lock.json;package-lock.json(if possible);If we decide to go with 1/2/3, we would need to manually intervene for any future alert, so 4/5 are better solutions in the long term. If we go with 4/5 it should be enough to list the
mainbranch independabot.ymlto solve the alerts since Dependabot only looks at themainbranch, unless we want to update deps on maintenance branches and/or keep all branches aligned.@hoodmane, do you have any preference?
Footnotes
https://github.com/python/cpython/pull/158394 ↩