Merged
Conversation
|
Member
Author
|
Relatedly: I don't know why https://github.com/sveltejs/svelte/security/dependabot/25 was seen as resolved by #11637. Maybe dependabot couldn't parse the new lockfile format and gave up? |
dummdidumm
approved these changes
Jun 25, 2024
FoHoOV
pushed a commit
to FoHoOV/svelte
that referenced
this pull request
Jun 27, 2024
* apply proper xml2js override * update lockfile
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#10133 didn't actually work. If you look at the lockfile (and at the diff in that PR), we're still on the old version of xml2js.
jimp>xml2jsonly overrides xml2js as a direct dependency of jimp, and it's not a direct dependency. Rather than specifying a precise but correct selector, I'd instead opted to just include a general one and override this dependency generally.Svelte 5 rewrite
Please note that the Svelte codebase is currently being rewritten for Svelte 5. Changes should target Svelte 5, which lives on the default branch (
main).If your PR concerns Svelte 4 (including updates to svelte.dev.docs), please ensure the base branch is
svelte-4and notmain.Before submitting the PR, please make sure you do the following
feat:,fix:,chore:, ordocs:.Tests and linting
pnpm testand lint the project withpnpm lint