chore: disable renovate for cookie package#15486
Conversation
|
@teemingc should stop the madness
|
Why this? I see you mention it's updated in v3 but v3 is not out and cookie 0.6.0 has a vulnerability jshttp/cookie#167 isn't it thoughtful to backport the vuln fix? |
|
Why this? I see you mention it's updated in v3 but v3 is not out and cookie 0.6.0 has a vulnerability jshttp/cookie#167 isn't it thoughtful to backport the vuln fix? It's because the vulnerability is quite esoteric, and it would be a very hard-to-diagnose breaking change to occur in a minor release. |
@teemingc should stop the madness