forked from Chia-Network/cadt-ui
-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
build(deps): bump the npm_and_yarn group across 2 directories with 12 updates #36
Closed
dependabot
wants to merge
1
commit into
main
from
dependabot/npm_and_yarn/build_scripts/npm_macos/npm_and_yarn-security-group-ac5a76c218
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
… updates Bumps the npm_and_yarn group with 7 updates in the /build_scripts/npm_macos directory: | Package | From | To | | --- | --- | --- | | [semver](https://github.com/npm/node-semver) | `5.7.1` | `5.7.2` | | [minimatch](https://github.com/isaacs/minimatch) | `3.0.4` | `5.1.6` | | [electron-builder](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/electron-builder) | `22.14.13` | `24.12.0` | | [ansi-regex](https://github.com/chalk/ansi-regex) | `3.0.0` | `3.0.1` | | [follow-redirects](https://github.com/follow-redirects/follow-redirects) | `1.14.8` | `1.15.5` | | [got](https://github.com/sindresorhus/got) | `9.6.0` | `` | | [git-authors-cli](https://github.com/Kikobeats/git-authors-cli) | `1.0.37` | `1.0.49` | Updates `semver` from 5.7.1 to 5.7.2 - [Release notes](https://github.com/npm/node-semver/releases) - [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md) - [Commits](npm/node-semver@v5.7.1...v5.7.2) Updates `minimatch` from 3.0.4 to 5.1.6 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.4...v5.1.6) Updates `electron-builder` from 22.14.13 to 24.12.0 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/master/packages/electron-builder/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/v24.12.0/packages/electron-builder) Updates `ansi-regex` from 3.0.0 to 3.0.1 - [Release notes](https://github.com/chalk/ansi-regex/releases) - [Commits](chalk/ansi-regex@v3.0.0...v3.0.1) Updates `ejs` from 3.1.6 to 3.1.9 - [Release notes](https://github.com/mde/ejs/releases) - [Commits](mde/ejs@v3.1.6...v3.1.9) Updates `follow-redirects` from 1.14.8 to 1.15.5 - [Release notes](https://github.com/follow-redirects/follow-redirects/releases) - [Commits](follow-redirects/follow-redirects@v1.14.8...v1.15.5) Removes `got` Updates `git-authors-cli` from 1.0.37 to 1.0.49 - [Release notes](https://github.com/Kikobeats/git-authors-cli/releases) - [Changelog](https://github.com/Kikobeats/git-authors-cli/blob/master/CHANGELOG.md) - [Commits](Kikobeats/git-authors-cli@v1.0.37...v1.0.49) Updates `json5` from 2.2.0 to 2.2.3 - [Release notes](https://github.com/json5/json5/releases) - [Changelog](https://github.com/json5/json5/blob/main/CHANGELOG.md) - [Commits](json5/json5@v2.2.0...v2.2.3) Updates `minimist` from 1.2.5 to 1.2.8 - [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md) - [Commits](minimistjs/minimist@v1.2.5...v1.2.8) Updates `yargs-parser` from 20.2.9 to 21.1.1 - [Release notes](https://github.com/yargs/yargs-parser/releases) - [Changelog](https://github.com/yargs/yargs-parser/blob/main/CHANGELOG.md) - [Commits](yargs/yargs-parser@yargs-parser-v20.2.9...yargs-parser-v21.1.1) Updates `plist` from 3.0.4 to 3.1.0 - [Release notes](https://github.com/TooTallNate/node-plist/releases) - [Changelog](https://github.com/TooTallNate/plist.js/blob/master/History.md) - [Commits](https://github.com/TooTallNate/node-plist/commits) --- updated-dependencies: - dependency-name: semver dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: minimatch dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: electron-builder dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: ansi-regex dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: ejs dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: follow-redirects dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: got dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: git-authors-cli dependency-type: direct:production dependency-group: npm_and_yarn-security-group - dependency-name: json5 dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: minimist dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: yargs-parser dependency-type: indirect dependency-group: npm_and_yarn-security-group - dependency-name: plist dependency-type: indirect dependency-group: npm_and_yarn-security-group ... Signed-off-by: dependabot[bot] <[email protected]>
dependabot
bot
added
the
dependencies
Pull requests that update a dependency file
label
Feb 21, 2024
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/[email protected], npm/[email protected] |
Looks like these dependencies are up-to-date now, so this is no longer needed. |
dependabot
bot
deleted the
dependabot/npm_and_yarn/build_scripts/npm_macos/npm_and_yarn-security-group-ac5a76c218
branch
March 1, 2024 22:54
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 7 updates in the /build_scripts/npm_macos directory:
5.7.1
5.7.2
3.0.4
5.1.6
22.14.13
24.12.0
3.0.0
3.0.1
1.14.8
1.15.5
9.6.0
1.0.37
1.0.49
Updates
semver
from 5.7.1 to 5.7.2Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
f8cc313
chore: release 5.7.22f8fd41
fix: better handling of whitespace (#585)deb5ad5
chore:@npmcli/template-oss
@4
.16.0Maintainer changes
This version was pushed to npm by lukekarrys, a new releaser for semver since your current version.
Updates
minimatch
from 3.0.4 to 5.1.6Changelog
Sourced from minimatch's changelog.
... (truncated)
Commits
3e216b9
5.1.64d0b7f5
Detect leading dots in extglob subpatterns9556826
5.1.5919c856
Count closing parens when closing excess open parens8d5cd74
publish legacy v5 version857a631
5.1.4d2c654d
Do not apply magic unnecessarily for nocase5878cf2
chore: add copyright year to license9b42a9c
5.1.349ae7a2
Fix end-anchoring of negative extglobsUpdates
electron-builder
from 22.14.13 to 24.12.0Release notes
Sourced from electron-builder's releases.
... (truncated)
Changelog
Sourced from electron-builder's changelog.
... (truncated)
Commits
17b5081
chore(deploy): Release v24.12.0 (#7981)fc13810
chore(deploy): Release v24.11.0 ([email protected]) (#7954)47e66ca
chore(deploy): Release v24.10.0 (#7934)a8fda9a
chore(deploy): Release v24.9.4 (#7916)512fb9e
chore(deploy): Release v24.9.3 (#7909)3973c66
chore(deploy): Release v24.9.2 (#7899)7ec7ac8
chore(deploy): Release v24.9.1 (#7888)abf52ea
chore(deploy): Release v24.9.0 (#7876)4791c83
chore(deploy): Release v24.8.1 ([email protected]) (#7847)4c9b829
chore(deploy): Release 24.8.0 ([email protected]) (#7825)Updates
ansi-regex
from 3.0.0 to 3.0.1Commits
f545bdb
3.0.1c57d4c2
fix a few old XO issues for backport419250f
Fix potential ReDoS (#37)Updates
ejs
from 3.1.6 to 3.1.9Release notes
Sourced from ejs's releases.
Commits
aed0124
Version 3.1.97083793
Updated dev deps87f1da6
Merge pull request #707 from mde/dependabot/npm_and_yarn/minimatch-3.1.2e41a914
Removed old changelog, please rely on git log9ea36ba
Merge pull request #719 from jportner/frozen-prototype-fix181a537
Fall back to assignment, update test58bc2eb
Change approach to shadowing "toString" property for escapeXML76c9c61
Bump minimatch from 3.0.4 to 3.1.2f818bce
Merge pull request #706 from mde/dependabot/npm_and_yarn/flat-and-mocha-5.0.20fca863
Bump flat and mochaUpdates
follow-redirects
from 1.14.8 to 1.15.5Commits
b1677ce
Release version 1.15.5 of the npm package.d8914f7
Preserve fragment in responseUrl.6585820
Release version 1.15.4 of the npm package.7a6567e
Disallow bracketed hostnames.05629af
Prefer native URL instead of deprecated url.parse.1cba8e8
Prefer native URL instead of legacy url.resolve.72bc2a4
Simplify _processResponse error handling.3d42aec
Add bracket tests.bcbb096
Do not directly set Error properties.192dbe7
Release version 1.15.3 of the npm package.Removes
got
Updates
git-authors-cli
from 1.0.37 to 1.0.49Release notes
Sourced from git-authors-cli's releases.
Changelog
Sourced from git-authors-cli's changelog.
Commits
41e7aa7
chore(release): 1.0.495289c88
build: tweaks67ac845
chore(release): 1.0.4896b92fa
refactor: use tinyspawn63e7493
chore(release): 1.0.47ff16f06
refactor: avoid exists-file7727df2
chore(release): 1.0.464014eb8
refactor: drop update-notifier40bb226
chore(release): 1.0.451588999
build: tweaksUpdates
json5
from 2.2.0 to 2.2.3Release notes
Sourced from json5's releases.
Changelog
Sourced from json5's changelog.
Commits
c3a7524
2.2.394fd06d
docs: update CHANGELOG for v2.2.33b8cebf
docs(security): use GitHub security advisoriesf0fd9e1
docs: publish a security policy6a91a05
docs(template): bug -> bug report14f8cb1
2.2.210cc7ca
docs: update CHANGELOG for v2.2.27774c10
fix: add proto to objects and arraysedde30a
Readme: slight tweak to intro97286f8
Improve example in readmeUpdates
minimist
from 1.2.5 to 1.2.8Changelog
Sourced from minimist's changelog.
... (truncated)
Commits
6901ee2
v1.2.8a026794
Merge tag 'v0.2.3'c0b2661
v0.2.363b8fee
[Fix] Fix long option followed by single dash (#17)72239e6
[Tests] Remove duplicate test (#12)34b0f1c
[eslint] fix indentation3226afa
[Dev Deps] add missingnpmignore
dev dep098873c
[Dev Deps] update@ljharb/eslint-config
,aud
9ec4d27
[Fix] Fix long option followed by single dashba92fe6
[actions] Avoid 0.6 tests due to build failuresMaintainer changes
This version was pushed to npm by ljharb, a new releaser for minimist since your current version.
Updates
yargs-parser
from 20.2.9 to 21.1.1Release notes
Sourced from yargs-parser's releases.
Changelog
Sourced from yargs-parser's changelog.
Commits
3aba24c
chore(main): release yargs-parser 21.1.1 (#455)d69f9c3
fix(typescript): ignore .cts files during publish (#454)90067a0
chore(main): release yargs-parser 21.1.0 (#446)d07bcdb
fix: node version check now uses process.versions.node (#450)c0c6079
chore(deps): update dependency puppeteer to v16 (#451)a89259f
feat: allow the browser build to be imported (#443)c474bc1
fix(halt-at-non-option): prevent known args from being parsed when "unknown-o...fd30238
chore(deps): update dependency serve to v14 (#449)a072f9a
chore(deps): update dependency puppeteer to v15 (#444)4f1060b
fix: parse options ending with 3+ hyphens (#434)Updates
plist
from 3.0.4 to 3.1.0Changelog
Sourced from plist's changelog.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.