Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency balena-io/balena-cli to v18.2.33 #375

Merged
merged 1 commit into from
Jul 25, 2024

Conversation

balena-renovate[bot]
Copy link
Contributor

This PR contains the following updates:

Package Update Change
balena-io/balena-cli patch v18.2.2 -> v18.2.33

Release Notes

balena-io/balena-cli (balena-io/balena-cli)

v18.2.33

Compare Source

v18.2.32

Compare Source

v18.2.31

Compare Source

a39a772 (Deduplicate dependencies, 2024-07-15)
efa0d67 (deploy: Use the sdk's pine instance with balena-compose, 2024-07-15)
232b967 (Update balena-sdk to 19.7.3, 2024-07-13)

v18.2.30

Compare Source

4e101e2 (Omit unicode control character escapes from test logs, 2024-07-13)
9f9fd97 (Deduplicate dependencies, 2024-07-13)

v18.2.29

Compare Source

3c64e13 (Update balena-preload from 15.0.5 to 15.0.6, 2024-07-11)

v18.2.28

Compare Source

79fcd95 (Downgrade pinejs-client-request to 7.4.2 to unblock the sdk update, 2024-07-12)
33199ac (Update balena-sdk to 19.7.2, 2024-07-12)

v18.2.27

Compare Source

1702f8b (Update balena-sdk to 19.5.5, 2024-07-12)

v18.2.26

Compare Source

1bc0f74 (Drop unused dependencies, 2024-07-11)
f65215e (Move dependencies that should be dev only as devDependencies, 2024-07-11)

v18.2.25

Compare Source

b1073ca (Fix complete generation intermitency, 2024-07-10)
e659e35 (Bump oclif to v4, 2024-07-10)

v18.2.24

Compare Source

19a60bb (Update mocha from 8.4.0 to 10.6.0, 2024-07-10)
d1a6f75 (Override inline-source-cli with non-vulnerable dependency, 2024-07-10)

v18.2.23

Compare Source

7273656 (Replace resin-discoverable-services with bonjour-service, 2024-07-09)

v18.2.22

Compare Source

1749937 (Remove unused dependency minimatch, 2024-07-10)

v18.2.21

Compare Source

6c89ba4 (Bump resin-discoverable-services from 2.0.4 to 2.0.5, 2024-07-09)

v18.2.20

Compare Source

b6d1afa (Audit fix dependencies, 2024-07-05)

v18.2.19

Compare Source

93e597a (Remove unused package publish-release, 2024-07-05)

v18.2.18

Compare Source

Update actions/setup-node action to v4

Notable changes
actions/setup-node (actions/setup-node)
v4

Compare Source

List of commits

c30a1dc (Update actions/setup-node action to v4, 2024-07-02)

v18.2.17

Compare Source

Update dependency etcher-sdk to v9.1.0

Notable changes
  • patch: etcher-sdk is not yet compatible with node22 [JOASSART Edwin]
  • minor: allow passing custom assets to start SB protected CM4 [Edwin Joassart]
balena-io-modules/etcher-sdk (etcher-sdk)
v9.1.0

Compare Source

  • patch: etcher-sdk is not yet compatible with node22 [JOASSART Edwin]
  • minor: allow passing custom assets to start SB protected CM4 [Edwin Joassart]
List of commits

2d47eb5 (Update dependency etcher-sdk to v9.1.0, 2024-07-02)

v18.2.16

Compare Source

Update dependency etcher-sdk to v9.0.11

Notable changes
  • patch: use http2 to fix issues with url source [Edwin Joassart]
  • patch: remove CI workaround [Edwin Joassart]
  • patch: add option to allow listing virtual drive on Mac [JOASSART Edwin]
balena-io-modules/etcher-sdk (etcher-sdk)
v9.0.11

Compare Source

  • patch: use http2 to fix issues with url source [Edwin Joassart]
v9.0.10

Compare Source

  • patch: remove CI workaround [Edwin Joassart]
v9.0.9

Compare Source

  • patch: add option to allow listing virtual drive on Mac [JOASSART Edwin]
List of commits

6b56576 (Update dependency etcher-sdk to v9.0.11, 2024-07-02)

v18.2.15

Compare Source

Update dependency event-stream to v3.3.5

Notable changes
dominictarr/event-stream (event-stream)
v3.3.5

Compare Source

List of commits

b518067 (Update dependency event-stream to v3.3.5, 2024-07-02)

v18.2.14

Compare Source

Update dependency jsonwebtoken to v9 [SECURITY]

Notable changes
  • Removed support for Node versions 11 and below.
  • The verify() function no longer accepts unsigned tokens by default. ([8345030]auth0/node-jsonwebtoken@8345030)
  • RSA key size must be 2048 bits or greater. ([ecdf6cc]auth0/node-jsonwebtoken@ecdf6cc)
  • Key types must be valid for the signing / verification algorithm
  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539
auth0/node-jsonwebtoken (jsonwebtoken)
v9.0.0

Compare Source

Breaking changes: See Migration from v8 to v9

Breaking changes
Security fixes
  • security: fixes Arbitrary File Write via verify function - CVE-2022-23529
  • security: fixes Insecure default algorithm in jwt.verify() could lead to signature validation bypass - CVE-2022-23540
  • security: fixes Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC - CVE-2022-23541
  • security: fixes Unrestricted key type could lead to legacy keys usage - CVE-2022-23539
List of commits

f05e499 (Update dependency jsonwebtoken to v9 [SECURITY], 2024-07-02)

v18.2.13

Compare Source

14e1255 (Update dependency @​types/prettyjson to ^0.0.33, 2024-07-02)

v18.2.12

Compare Source

7325e8d (Deduplicate dependencies, 2024-07-01)

v18.2.11

Compare Source

a29bd8d (Update dependency @​types/fast-levenshtein to v0.0.4, 2024-06-21)

v18.2.10

Compare Source

Update actions/download-artifact action to v4.1.7

Notable changes
actions/download-artifact (actions/download-artifact)
v4.1.7

Compare Source

What's Changed

Full Changelog: actions/download-artifact@v4.1.6...v4.1.7

v4.1.6

Compare Source

What's Changed

Full Changelog: actions/download-artifact@v4.1.5...v4.1.6

v4.1.5

Compare Source

What's Changed

Full Changelog: actions/download-artifact@v4.1.4...v4.1.5

v4.1.4

Compare Source

What's Changed

Full Changelog: actions/download-artifact@v4...v4.1.4

v4.1.3

Compare Source

What's Changed
New Contributors

Full Changelog: actions/download-artifact@v4...v4.1.3

v4.1.2

Compare Source

v4.1.1

Compare Source

List of commits

15c0c32 (Update actions/download-artifact action to v4.1.7, 2024-06-21)

v18.2.9

Compare Source

7322020 (Update actions/setup-python digest to 65d7f2d, 2024-06-21)

v18.2.8

Compare Source

2cd455f (Update actions/upload-artifact digest to 6546280, 2024-06-21)

v18.2.7

Compare Source

f502878 (Pin dependencies, 2024-06-21)

v18.2.6

Compare Source

75d2d7d (Update @​oclif/core from 3.26.9 to 3.27.0, 2024-06-21)

v18.2.5

Compare Source

5a3f0ea (Limit @​oclif/core to ~3.26 so that npm dedupe doesn't auto-bump it, 2024-06-21)
e1cd300 (Deduplicate dependencies, 2024-06-21)
7959e23 (Update TypeScript to 5.5.2, 2024-06-21)


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

Update balena-io/balena-cli from 18.2.2 to 18.2.33

Change-type: patch
@balena-renovate balena-renovate bot enabled auto-merge July 25, 2024 13:51
@balena-renovate balena-renovate bot merged commit a065bbe into master Jul 25, 2024
51 checks passed
@balena-renovate balena-renovate bot deleted the renovate/balena-io-balena-cli-18.2.x branch July 25, 2024 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants