Konstantin Mizev
Konstantin Mizev
According to [update-script.rb#L314](https://github.com/tinglesoftware/dependabot-azure-devops/blob/main/src/script/update-script.rb#L314) it allows security updates even if dependency is outside of `allow` list, so you can do a bit of hack with: `DEPENDABOT_ALLOW_CONDITIONS: '[{"dependency-name":"a1","dependency-type":"all"}]' # specify any non-existing...
This backport would be extremely helpful
There is version [6.11.4](https://www.npmjs.com/package/protobufjs/v/6.11.4) published to NPM, however there was no explicit changelog or other announcement. According to commits, [changes are about the requested backport](https://github.com/protobufjs/protobuf.js/commits/release-6.11.4)