Skip to content

Conversation

ChristophWurst
Copy link
Member

@ChristophWurst ChristophWurst commented Sep 12, 2025

This will allow us to have separate PRs for vulnerabilities reported by npm audit. The current limitation is that it will update wildly, often touching packages that don't even need updating, so it's a useless upgrade risk.

The workflow does not run automatically at the moment because it needs to be triggered for each branch. I think manually triggering it is fine when we see an automated npm audit fix PR that touches more than it should.

Signed-off-by: Christoph Wurst <christoph@winzerhof-wurst.at>
@ChristophWurst ChristophWurst force-pushed the ci/selective-npm-audit-fix branch from 30addb8 to 51caba7 Compare September 17, 2025 12:31
@ChristophWurst ChristophWurst marked this pull request as ready for review September 17, 2025 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant