[Snyk] Security upgrade lerna from 5.6.2 to 8.1.9#814
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-JSYAML-17900054 - https://snyk.io/vuln/SNYK-JS-TAR-17909068 - https://snyk.io/vuln/SNYK-JS-TAR-17909104 - https://snyk.io/vuln/SNYK-JS-TAR-17909152 - https://snyk.io/vuln/SNYK-JS-TAR-17909225
|
This upgrade spans three major versions (v6, v7, v8) and introduces significant breaking changes that will require migration effort. The core philosophy of Lerna has shifted towards leveraging package manager workspaces and the Nx task runner. Key Breaking Changes:
Recommendation:
Source: Lerna Changelog, Legacy Package Management Guide
|
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
Snyk has created this PR to fix 5 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-JSYAML-17900054
SNYK-JS-TAR-17909068
SNYK-JS-TAR-17909104
SNYK-JS-TAR-17909152
SNYK-JS-TAR-17909225
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling
🦉 Uncaught Exception