Switch from yarn
to npm
and block vulnerable ndarray-resample
#83
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fixes #82.
It doesn't seem possible to resolve the vulnerability caused by
ndarray-resample
just by updating packages, as I explained in #82. For this reason, I just blockndarray-resample
and its dependencies from being installed by overriding it with thedry-uninstall
dummy package.The package builds and works correctly but I'm not sure that this doesn't break anything for downstream packages. What I do know is that we're not using any functionality of
@magenta/music
that usesndarray-resample
, so... it should be fine?