Upgrade cpy-cli to latest version #46
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Upgrade dependency
cpy-clito latest version to remove vulnerabilities in transitive dependencies, most importantly intrim-newlines,Results of running
yarn audit --groups dependencies --no-lockfile(install dependencies as if your pakage depended on it and all versions resolved to the newest available):Before upgrading:
Severity: 8 Low | 8 Moderate | 7 HighAfter upgrading:
Severity: 10 Low | 6 Moderate | 5 HighI also tried upgrading opn-cli, but that required code changes. I may do it in a separate PR if I find the time.
Warning:
cpy-cli>=3requires node.js 8. This may be a breaking change; I was unfortunately not able to find the currently required version.