Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

meta: specify tag when using npx #50517

Draft
wants to merge 1 commit into
base: main
Choose a base branch
from
Draft

Conversation

H4ad
Copy link
Member

@H4ad H4ad commented Nov 1, 2023

I don't know if I selected the correct subsystem, so feel free to suggest if I selected the wrong one.

Since we pin Github Actions by commit hash, I think is reasonable to pin npx packages by version, accords to https://docs.npmjs.com/policies/unpublish is safe to assume those versions will not be changed.

cc @nodejs/security

@nodejs-github-bot
Copy link
Collaborator

Review requested:

  • @nodejs/actions

@nodejs-github-bot nodejs-github-bot added the meta Issues and PRs related to the general management of the project. label Nov 1, 2023
@H4ad H4ad requested a review from RafaelGSS November 1, 2023 23:59
@H4ad H4ad changed the title build: specify tag when using npx meta: specify tag when using npx Nov 2, 2023
@marco-ippolito
Copy link
Member

marco-ippolito commented Nov 2, 2023

Are these versions going to be updated by tooling or they are hardcoded forever?

@H4ad
Copy link
Member Author

H4ad commented Nov 2, 2023

Probably hardcoded forever, I don't think the current tooling will bump versions of packages that runs npx.

@marco-ippolito
Copy link
Member

marco-ippolito commented Nov 2, 2023

-1 I dont think it's a good idea, to have hardcoded dependency version

Copy link
Member

@RafaelGSS RafaelGSS left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If dependabot doesn't automatically update it, I'm -1.

@H4ad
Copy link
Member Author

H4ad commented Nov 2, 2023

I will keep as draft for now until I got an answer from dependabot/dependabot-core#8322

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
meta Issues and PRs related to the general management of the project.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants