-
-
Notifications
You must be signed in to change notification settings - Fork 41
Bump to Yarn v4 #222
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: bump-dev-and-test-node
Are you sure you want to change the base?
Bump to Yarn v4 #222
Conversation
Don't bring over all of the GitHub workflows from the module template, but use the `checkout-and-setup` action so that we don't get errors about using a deprecated version of `actions/cache`.
Bumping the development version of Node to 22 specifically allows us to upgrade to Yarn v4.
New dependencies detected. Learn more about Socket for GitHub ↗︎
|
👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎ This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. Ignoring: Next stepsTake a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with |
@SocketSecurity ignore npm/[email protected] Network access makes sense, Yarn is a CLI that requires an internet connection. New authors are OK, I have confirmed their legitimacy. |
Upgrading to v4 allows us to bring over more things from the module template, such as JavaScript constraints. 4.7.0 is the latest version at the time of this writing. Note that we do not need the `setup` package script anymore because `yarn install` already runs `yarn allow-scripts` automatically.
2a42c2c
to
c79d745
Compare
Upgrading to v4 allows us to bring over more things from the module template, such as JavaScript constraints.
4.7.0 is the latest version at the time of this writing.