Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
We've been getting misleading security reports about vulnerabilities in our dependency chain under this package, but it doesn't look like those things actually need to be
dependencies
. In particular, thenpm
dependency pulls in a version ofsemver
vulnerable to https://nvd.nist.gov/vuln/detail/CVE-2022-25883.While I don't believe this package really exposes our users to that vulnerability, I'd rather clean up the package than argue with our security team. This should also marginally improve install speed and reduce bloat where this package is used.
These dependencies were added with #169, and @ungap/structured-clone is a legitimate dependency. The @types package just needs to be listed as a dev dependency to get its goodness. I wasn't actually able to find any indication that the
i
package is in use, but would be happy to add it back in if there is need.