Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I get Dependabot alerts emailed to me, and this repository on the microformats org is one that keeps coming up. For others in the org, see Dependabot alerts. It currently lists 14 open issues.
The issues are with the Node.js dependencies included for running a local server exposing the tests.
This PR hopefully closes all those issues.
npm auditcomes back clean.I am split on the bump for
engines. It is not strictly necessary to have a newer version of Node.js to include the raw test files, but it is necessary to run the Hapi server. Although bumping it to Node.js 14.15 should hardly be a problem for anyone as that is the LTS version first published 2020-04-21... even for people running LTS Node.js they should be on something a little more recent.Side-note: the Hapi test server was actually broken for the last 8 years or so. 4785260 should have introduced the Hapi inert handling, but did not. If we would rather get rid of all the Node.js code, that is also fine with me.