dependabot-core
dependabot-core copied to clipboard
Dependabot missing caret signifier for alerts
I got this alert: Upgrade protobufjs to fix 1 Dependabot alert in functions/package-lock.json Upgrade protobufjs to version 7.2.5 or later. For example:
"dependencies": { "protobufjs": ">=7.2.5" } "devDependencies": { "protobufjs": ">=7.2.5" }
however my code has: "dependencies": { "protobufjs": "^7.2.5" }