Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Framework: Bump Lerna to v3.14.1 #15825

Merged
merged 1 commit into from
May 27, 2019
Merged

Framework: Bump Lerna to v3.14.1 #15825

merged 1 commit into from
May 27, 2019

Conversation

aduth
Copy link
Member

@aduth aduth commented May 25, 2019

This pull request seeks to bump the Lerna dependency from 3.13.2 to 3.14.1

Changelogs: https://github.com/lerna/lerna/releases

Notable benefits:

  • 3.14.0 introduced OTP prompts, which have historically been a huge pain-point for two-factor authorization publishes
  • It resolves a number of vulnerability advisories, decreasing from 36 vulnerabilities (34 high) to 12 vulnerabilities (10 high)

My expectation is that, as a project adhering to SemVer, and a version bump in the minor range, there should be no expectation of breaking changes to account for.

@aduth aduth added the Framework Issues related to broader framework topics, especially as it relates to javascript label May 25, 2019
@aduth aduth requested review from gziolo and ntwb May 25, 2019 00:50
Copy link
Member

@gziolo gziolo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for wrangling it, I will double check docs in the context of OTP and send a patch if necessary.

@gziolo gziolo added this to the 5.8 (Gutenberg) milestone May 27, 2019
@gziolo gziolo merged commit c464e9f into master May 27, 2019
@gziolo gziolo deleted the update/lerna-3-14 branch May 27, 2019 06:41
@gziolo
Copy link
Member

gziolo commented May 27, 2019

Opened a follow-up with the update to docs in #15835.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Framework Issues related to broader framework topics, especially as it relates to javascript
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants