deps: remove unused c8 and update cross-spawn resolution#16845
deps: remove unused c8 and update cross-spawn resolution#16845RinZ27 wants to merge 1 commit intoGoogleChrome:mainfrom
Conversation
|
I'd rather just update whatever dep is pulling this in. I think it's c8, which we don't really use anymore and should just remove. |
|
@connorjclark Agreed. If we're not using |
a80119f to
96348be
Compare
|
@connorjclark Done. I've stripped out |
KrrishSR4
left a comment
There was a problem hiding this comment.
Reviewed the changes.
Removing the unused c8 dependency makes sense and effectively addresses the cross-spawn vulnerability while reducing technical debt. Keeping the resolution as a safety net also looks reasonable.
LGTM 👍
|
@KrrishSR4 Appreciate the feedback! |
I removed
c8and its related coverage configurations since we're not really using it anymore. This naturally resolves the security alerts caused by the oldercross-spawnversion thatc8was pulling in, while also cleaning up some technical debt.I've also kept the
cross-spawnresolution just to be safe in case any other transitive deps are still hitting it, but the primary fix was stripping out the unused dependency as suggested.