[VOTE] cordova-lib 12.0.1 Release

2023-05-19 Thread Bryan Ellis
Please review and vote on this cordova-lib release v12.0.1 by replying to this email (and keep discussion on the DISCUSS thread) The archive has been published to dist/dev: https://dist.apache.org/repos/dist/dev/cordova/lib-12.0.1 The package was published from its corresponding git tag: co

[VOTE] Cordova-Android 12.0.0 Release

2023-05-19 Thread Bryan Ellis
Please review and vote on this Cordova-Android Release v12.0.0 by replying to this email (and keep discussion on the DISCUSS thread) The archive has been published to dist/dev: https://dist.apache.org/repos/dist/dev/cordova/android-v12.0.0 The package was published from its corresponding git

Re: [VOTE] cordova-lib 12.0.1 Release

2023-05-19 Thread Norman Breau
I vote +1: - Verified Archive - Verified Tags - NPM Audit is green On 2023-05-19 12:37 p.m., Bryan Ellis wrote: Please review and vote on this cordova-lib release v12.0.1 by replying to this email (and keep discussion on the DISCUSS thread) The archive has been published to dist/dev: https://

Re: [VOTE] Cordova-Android 12.0.0 Release

2023-05-19 Thread Norman Breau
I vote +1: - Ran NPM Test locally (on linux) - Verified Archive - Verified Tags - NPM Audit is green On 2023-05-19 1:28 p.m., Bryan Ellis wrote: Please review and vote on this Cordova-Android Release v12.0.0 by replying to this email (and keep discussion on the DISCUSS thread) The archive has

[VOTE] cordova-cli 12.0.0 Release

2023-05-19 Thread Bryan Ellis
Please review and vote on this cordova-cli release v12.0.0 by replying to this email (and keep discussion on the DISCUSS thread) The archive has been published to dist/dev: https://dist.apache.org/repos/dist/dev/cordova/cli-12.0.0 The package was published from its corresponding git tag: co

Re: [VOTE] cordova-cli 12.0.0 Release

2023-05-19 Thread Norman Breau
I vote +1: - Verified Archive - Verified Tags - Local Linux NPM test passes - NPM audit 2 moderate vulnerabilities from `request` (https://github.com/advisories/GHSA-p8p7-x288-28g6).  See DISCUSS thread for rationale on this issue. On 2023-05-19 2:07 p.m., Bryan Ellis wrote: Please review and

Re: [DISCUSS] cordova-cli 12.0.0 Release

2023-05-19 Thread Norman Breau
The rationale behind releasing with the `request` vulnerabilities: We are looking for ways to drop/replace the insight package, which is the package that is importing `request`. Insight collects anonymous telemetry data and thus we believe in good faith that the impact on Cordova is low and no