Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump node-notifier from 5.4.3 to 10.0.0 in /src/client #298

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github May 26, 2021

Bumps node-notifier from 5.4.3 to 10.0.0.

Changelog

Sourced from node-notifier's changelog.

v10.0.0

Breaking changes:

Setting NSAllowsArbitraryLoads as false for security reasons within terminal-notifier. Meaning non-https images/loads for terminal-notifier will no longer work. See #362

Fixes

  • fix: options.customPath doesn't work for windows toaster. See #373

v9.0.1

  • Fixes potential security issue with non-escaping input parameters for notify-send.

v9.0.0

Breaking changes:

  • Corrects mapping on snoretoast activate event. See #347.

Patches

  • Fix named pipe in WSL. See #342.
  • fixes possible injection issue for notify-send

v8.0.2

  • Fixes potential security issue with non-escaping input parameters for notify-send.

v8.0.0

Breaking changes:

  • Expire time for notify-send is made to match macOS and Windows with default time of 10 seconds. The API is changed to take seconds as input and converting it to milliseconds before passing it on to notify-send. See #341.

v7.0.2

  • Updates dependencies
  • Fixes issue with haning Windows notifications when disabled (#335)

v7.0.1

  • Fixes import of uuid, removes deprecation warnings

v7.0.0

Features

  • NotifySend support for app-name (#299, see docs)

... (truncated)

Commits
  • 2c237b1 v10.0.0
  • 4b3af8b updates changelog
  • 1265ee3 chore: updates dependencies
  • b9427d4 Merge pull request #374 from mikaelbr/dependabot/npm_and_yarn/hosted-git-info...
  • 14af678 Merge pull request #362 from idhruvs/master
  • 4a4d25c Merge pull request #368 from mikaelbr/dependabot/npm_and_yarn/y18n-4.0.1
  • 61c02ce Bump lodash from 4.17.19 to 4.17.21 (#372)
  • c1b2e66 fix: options.customPath doesn't work for windows toaster (#373)
  • 85a7cc5 Bump hosted-git-info from 2.8.8 to 2.8.9
  • d66249d Bump y18n from 4.0.0 to 4.0.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label May 26, 2021
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/src/client/node-notifier-10.0.0 branch from 036dcc8 to 7b550b8 Compare November 14, 2021 02:29
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Feb 2, 2022

Superseded by #314.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants