[Snyk] Security upgrade @vscode/extension-telemetry from 0.8.5 to 0.9.0#14376
Conversation
…thon/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-OPENTELEMETRYCORE-17373280
|
This is a minor version upgrade. The release notes for version 0.9.0 indicate that the changes are limited to internal dependency updates and a migration of the project's linting configuration. There are no documented API changes or breaking changes for consumers of the package. Changes in v0.9.0:
Source: GitHub Releases
|
|
E2E Tests 🚀 |
|
@austin3dickey can you evaluate if we should take this bump? We turn off all the Microsoft telemetry but having the version that triggers security checks is not good for us. |
|
The upstream change that bumps this is microsoft/vscode-python#26007, which bumps the major version. But this minor version bump should be fine in the meantime while we wait for that to be merged. |
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
extensions/positron-python/package.jsonextensions/positron-python/package-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-OPENTELEMETRYCORE-17373280
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling