Update retire.js to 2.2.5
Problem to solve
retire.js 2.2.5
is available, we should consider upgrading our analyzer.
Proposal
Please carefully check the how to update the upstream Scanner.
Or follow the default workflow:
-
review the changelog -
update the pinned version (in the Dockerfile or script or template, the mileage may vary) -
make sure all test passes
Testing
-
Check relevant test projects leveraging retire.js and make sure QA pipelines are passing with this new version: QA projects for Dependency Scanning
What does success look like, and how can we measure that?
Our feature is leveraging the latest version (2.2.5
) of retire.js.