Skip to content

fix: update critical lockfile dependencies#237

Closed
lancewillett wants to merge 1 commit into
trunkfrom
fix/critical-lockfile-alerts
Closed

fix: update critical lockfile dependencies#237
lancewillett wants to merge 1 commit into
trunkfrom
fix/critical-lockfile-alerts

Conversation

@lancewillett
Copy link
Copy Markdown

Summary

Updates the npm lockfile to clear the critical Dependabot alerts for transitive basic-ftp and handlebars.

Testing

  • npm audit --audit-level critical --json reports 0 criticals
  • npm ci --ignore-scripts
  • npm run lint
  • git diff --check
  • git verify-commit HEAD

No test script is defined in this package.

@lancewillett lancewillett requested a review from a team as a code owner June 1, 2026 00:49
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Jun 1, 2026

👋 Thanks for your interest in contributing to Newspack!

Newspack development has moved to a single monorepo: Automattic/newspack-workspace. This repository is now a read-only mirror, so we're automatically closing new pull requests here.

Please reopen your change against the monorepo – newspack-scripts now lives at packages/scripts/ there. Thank you! 💙

@github-actions github-actions Bot closed this Jun 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant