Skip to content

Commit

Permalink
chore: pin cspell version
Browse files Browse the repository at this point in the history
This package has a lot of transient dependencies, resulting in considerable supply chain risk. By pinning its version, we can ensure its dependencies won‘t be updated until we manually update cspell, which should be done through a pull request, so Socket.dev can alert us of malicious packages and other security vulnerabilities. Note that version pinning is only effective when cspell is installed with a lockfile.
  • Loading branch information
aleclarson committed Nov 17, 2024
1 parent 8d31800 commit a33e5a4
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@
"@radashi-org/biome-config": "link:scripts/biome-config",
"@types/node": "^22.7.7",
"@vitest/coverage-v8": "2.1.5",
"cspell": "^8.13.3",
"cspell": "8.15.4",
"prettier": "^3.3.2",
"prettier-plugin-pkg": "^0.18.1",
"prettier-plugin-sh": "^0.14.0",
Expand Down
2 changes: 1 addition & 1 deletion pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

0 comments on commit a33e5a4

Please sign in to comment.