Skip to content

Conversation

@Jym77
Copy link
Contributor

@Jym77 Jym77 commented Oct 3, 2024

  • Remove the old request dependency, replacing it with axios. The fetch seems to work the same way. This should clean almost all security issues reported by Dependabot.
  • Switch from yarn v1 to berry (v4).
  • Bump semver, cleaning another security issue.

There should be only one security issue left, depending on json-ld, we probably want another PR for that given how "handling JSON-LD" is central to this repo.
There are quite a bunch of other possible updates and code modernisation, also for another PR.

@Jym77 Jym77 self-assigned this Oct 3, 2024
@Jym77 Jym77 changed the title Update yarn and dedupe dependencies Remove request, update yarn and dedupe dependencies Feb 2, 2026
Copy link
Contributor

@daniel-montalvo daniel-montalvo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks much @Jym77

@Jym77 Jym77 merged commit 78c1c32 into main Feb 3, 2026
1 check passed
@Jym77 Jym77 deleted the update-yarn branch February 3, 2026 09:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants