Skip to content
This repository was archived by the owner on Mar 27, 2026. It is now read-only.

Remove yarn lockfile and cache from test-package-json example#434

Closed
dependabot[bot] wants to merge 6 commits intomainfrom
dependabot/npm_and_yarn/examples/code-scanning/test-package-json/cross-spawn-7.0.6
Closed

Remove yarn lockfile and cache from test-package-json example#434
dependabot[bot] wants to merge 6 commits intomainfrom
dependabot/npm_and_yarn/examples/code-scanning/test-package-json/cross-spawn-7.0.6

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 24, 2025

Summary

Removes yarn artifacts (yarn.lock, .pnp.cjs, .pnp.loader.mjs, .yarn/ cache) from the examples/code-scanning/test-package-json/ directory. Also removes the packageManager field from its package.json.

These files are not read by the code scanning logic (which only parses package.json) and were the source of recurring dependabot alerts for transitive dependencies like cross-spawn, brace-expansion, sequelize, etc.

Test plan

  • findCodePackagesInFolder test passes — it only reads package.json contents

Bumps [cross-spawn](https://github.com/moxystudio/node-cross-spawn) from 7.0.3 to 7.0.6.
- [Changelog](https://github.com/moxystudio/node-cross-spawn/blob/master/CHANGELOG.md)
- [Commits](moxystudio/node-cross-spawn@v7.0.3...v7.0.6)

---
updated-dependencies:
- dependency-name: cross-spawn
  dependency-version: 7.0.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 24, 2025
Resolve Yarn PnP conflicts by regenerating .pnp.cjs and install-state.gz.

Made-with: Cursor
These yarn artifacts (yarn.lock, .pnp.cjs, .pnp.loader.mjs, .yarn/)
are not used by code scanning tests and only trigger unnecessary
dependabot alerts for transitive dependencies like cross-spawn.

Made-with: Cursor
@michaelfarrell76 michaelfarrell76 changed the title Bump cross-spawn from 7.0.3 to 7.0.6 in /examples/code-scanning/test-package-json Remove yarn lockfile and cache from test-package-json example Mar 18, 2026
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Mar 18, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/examples/code-scanning/test-package-json/cross-spawn-7.0.6 branch March 18, 2026 21:05
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant