-
-
Notifications
You must be signed in to change notification settings - Fork 1
chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates #620
base: main
Are you sure you want to change the base?
chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates #620
Conversation
…dates Bumps the npm_and_yarn group with 5 updates in the /packages/app directory: | Package | From | To | | --- | --- | --- | | [electron-updater](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/electron-updater) | `5.3.0` | `6.3.4` | | [pubnub](https://github.com/pubnub/javascript) | `4.27.3` | `7.4.0` | | [ses](https://github.com/endojs/endo/tree/HEAD/packages/ses) | `0.12.7` | `1.8.0` | | [chromedriver](https://github.com/giggio/node-chromedriver) | `111.0.0` | `129.0.2` | | [gh-pages](https://github.com/tschaub/gh-pages) | `3.2.3` | `6.1.1` | Updates `electron-updater` from 5.3.0 to 6.3.4 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/master/packages/electron-updater/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/[email protected]/packages/electron-updater) Updates `pubnub` from 4.27.3 to 7.4.0 - [Release notes](https://github.com/pubnub/javascript/releases) - [Changelog](https://github.com/pubnub/javascript/blob/master/CHANGELOG.md) - [Commits](pubnub/javascript@v4.27.3...v7.4.0) Updates `ses` from 0.12.7 to 1.8.0 - [Changelog](https://github.com/endojs/endo/blob/master/packages/ses/CHANGELOG.md) - [Commits](https://github.com/endojs/endo/commits/[email protected]/packages/ses) Updates `chromedriver` from 111.0.0 to 129.0.2 - [Commits](giggio/node-chromedriver@111.0.0...129.0.2) Updates `gh-pages` from 3.2.3 to 6.1.1 - [Release notes](https://github.com/tschaub/gh-pages/releases) - [Changelog](https://github.com/tschaub/gh-pages/blob/main/changelog.md) - [Commits](tschaub/gh-pages@v3.2.3...v6.1.1) --- updated-dependencies: - dependency-name: electron-updater dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: pubnub dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: ses dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: chromedriver dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: gh-pages dependency-type: direct:development dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected] |
🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎ To accept the risk, merge this PR and you will not be notified again.
Next stepsWhat is network access?This module accesses the network. Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use. Take a deeper look at the dependencyTake a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev. Remove the packageIf you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency. Mark a package as acceptable riskTo ignore an alert, reply with a comment starting with
|
Bumps the npm_and_yarn group with 5 updates in the /packages/app directory:
5.3.0
6.3.4
4.27.3
7.4.0
0.12.7
1.8.0
111.0.0
129.0.2
3.2.3
6.1.1
Updates
electron-updater
from 5.3.0 to 6.3.4Release notes
Sourced from electron-updater's releases.
... (truncated)
Changelog
Sourced from electron-updater's changelog.
... (truncated)
Commits
d5d9f3f
chore(deploy): Release v25.0.5 ([email protected]) (#8411)e77de9f
chore(deps): upgrade semver to latest to resolve CVE (#8417)15ce5b4
fix: changeabort
listener toaborted
event (#8282)5fae1cf
fix: windows signature verification special chars (#8409)1dcf6bc
chore(deploy): Release v25.0.4 ([email protected]) (#8402)1c14820
fix: handle spaces in artifact name for all linux platforms instead of only ....8dabf64
fix: add customchannel
in github provider (#8393)9dc0b49
fix(electron-updater,deb): Handle spaces in application artifact name for deb...84f2909
chore(deploy): Release v25.0.3 ([email protected]) (#8377)c8fe146
fix(updater): Add global download promise to limit concurrent update download...Updates
pubnub
from 4.27.3 to 7.4.0Release notes
Sourced from pubnub's releases.
... (truncated)
Changelog
Sourced from pubnub's changelog.
... (truncated)
Commits
fb6cd04
feat/CryptoModule (#339)d1fca58
CLEN-1556/fix/error handling when send file encounters issues (#338)3745862
added readme.md tutorial video. (#336)ff67973
CLEN-1504/fix/upgrade superagent (#337)8adfccd
fix/CLEN-1440 (#335)9584344
CLEN-1406/Fix proxy agent dependency upgrade (#331)40570e6
build(aws): switch AWS CLI auth to access key (#332)667cde9
build: add custom GHA large runner (#329)a8870c3
docs: update version and version bump regexp (#327)1ba2fa6
feat: optional param withHeartbeat to set state through heartbeat endpoint. (...Maintainer changes
This version was pushed to npm by client-engineering-bot, a new releaser for pubnub since your current version.
Updates
ses
from 0.12.7 to 1.8.0Changelog
Sourced from ses's changelog.
... (truncated)
Commits
Updates
chromedriver
from 111.0.0 to 129.0.2Commits
e25699d
Bump version to 129.0.27abba4d
Bump version to 129.0.1da9879c
Bump version to 129.0.0df46c5c
Bump version to 128.0.3b2a0982
Bump version to 128.0.287f9a87
Bump version to 128.0.1d95f797
Fix micromatch vulnerability718b040
Bump version to 128.0.0b914f40
Update Axiose2181e5
Bump version to 127.0.3Maintainer changes
This version was pushed to npm by giggio, a new releaser for chromedriver since your current version.
Updates
gh-pages
from 3.2.3 to 6.1.1Release notes
Sourced from gh-pages's releases.
... (truncated)
Changelog
Sourced from gh-pages's changelog.
... (truncated)
Commits
e98ba0f
6.1.1122872f
Log changes3312dc4
Merge pull request #535 from WillBAnders/fix/missing-cname-optionb6b8454
Add test for cnameExists, asserting it replaces the existing CNAME1c60556
Add debug logs for nojekyll/cname creation as recommended by@paymand
727d714
Merge pull request #539 from tschaub/dependabot/npm_and_yarn/eslint-8.56.02a53e76
Bump eslint from 8.55.0 to 8.56.096124af
Merge pull request #537 from tschaub/dependabot/npm_and_yarn/fs-extra-11.2.009076df
Merge pull request #538 from tschaub/dependabot/npm_and_yarn/eslint-8.55.08135495
Bump eslint from 8.53.0 to 8.55.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.