Patch | Fix dependency version issues #68
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
The Node/Axios versions were updated in this PR to address security vulnerabilities. We applaud the update but unfortunately the change was made to the wrong file - the generated package.json was updated instead of the template file. When the next automated generation ran, it overwrote those changes and reverted to the vulnerable versions.
This fixes that by:
package.mustachewhich is the template used during generationA couple of minor fixes were done in addition, updated
cleanscript to preservetmp/and ignorepackage-lock.jsonfile since this should be handled locally by package consumers.