-
-
Notifications
You must be signed in to change notification settings - Fork 3.1k
Open
Labels
area: repository toolingconcerning ease of contributionconcerning ease of contributioncore-teamissues which must be handled by Mocha's core teamissues which must be handled by Mocha's core teamstatus: blockedWaiting for something else to be resolvedWaiting for something else to be resolvedtype: featureenhancement proposalenhancement proposal
Description
Tooling Suggestion Checklist
- I have tried restarting my IDE and the issue persists.
- I have pulled the latest
masterbranch of the repository. - I have read and agree to Mocha's Code of Conduct and Contributing Guidelines
- I have searched for related issues and issues with the
faqlabel, but none matched my issue. - I want to provide a PR to resolve this
Overview
There are quite a few issues on this repo right now tracking out-of-date packages. We're going to enable Renovate to automatically create PRs to update packages.
Notes from @boneskull:
Looks reasonable. The only thing I’d suggest with the automated tooling (something like Renovate, yeah?) is to have a human in the loop for production dependency upgrades—check them closely. Mocha has been bitten several times due to semver violations in its dependency tree. I would also recommend using https://socket.dev/ as well (should be free for OSS). While Mocha hasn’t been hit by a malicious dep (to my knowledge), historical performance is not a guarantee of future results. 😄
Additional Info
No response
voxpelli
Metadata
Metadata
Assignees
Labels
area: repository toolingconcerning ease of contributionconcerning ease of contributioncore-teamissues which must be handled by Mocha's core teamissues which must be handled by Mocha's core teamstatus: blockedWaiting for something else to be resolvedWaiting for something else to be resolvedtype: featureenhancement proposalenhancement proposal
Type
Projects
Status
Backlog