Skip to content

Bump @actions/core to 1.9.1 - #56

Merged
ilammy merged 1 commit into
masterfrom
audit
Aug 28, 2022
Merged

ilammy merged 1 commit into
masterfrom
audit

Conversation

@ilammy

@ilammy ilammy commented Aug 28, 2022

Copy link
Copy Markdown
Owner

Fixes CVE-2022-35954. Does not look like anything terriblity important
to me, but hey, audit is happy.
@ilammy

ilammy commented Aug 28, 2022

Copy link
Copy Markdown
Owner Author

Oh wow, now it pulls in a bunch of dependencies 😢

RIP going months without a CVE in the codebase. Bracing for getting notifications about them every week.

@ilammy
ilammy merged commit fe44a12 into master Aug 28, 2022
@ilammy
ilammy deleted the audit branch August 28, 2022 07:38
@pzhlkj6612

Copy link
Copy Markdown
Contributor

well, the "node_modules" entry in .gitignore didn't work?

@ilammy

ilammy commented Aug 29, 2022

Copy link
Copy Markdown
Owner Author

Hm... Seems to be something with my local clone 😞 When I prepared the change, I saw updates in node_modules, so naturally git added them. I think that was some remnant of the past, or something.

I believe node_modules with production dependencies is needed only on the release branch, since actions expect everything to be vendored and ready for them.

@pzhlkj6612

Copy link
Copy Markdown
Contributor

IIRC, adding a Git-ignored item is not that easy: git - Force add despite the .gitignore file - Stack Overflow.

Anyway, I've seen #57 and it's alright now. :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants