Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump async from 2.6.3 to 2.6.4 in /js/react_native/e2e #11280

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 20, 2022

Bumps async from 2.6.3 to 2.6.4.

Changelog

Sourced from async's changelog.

v2.6.4

  • Fix potential prototype pollution exploit (#1828)
Commits
Maintainer changes

This version was pushed to npm by hargasinski, a new releaser for async since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js/react_native/e2e/async-2.6.4 branch 2 times, most recently from fc5add4 to 7b6f906 Compare May 4, 2022 06:42
tianleiwu
tianleiwu previously approved these changes May 23, 2022
@hanbitmyths
Copy link
Contributor

/azp run Linux, CPU CI Pipeline , Linux CPU x64 NoContribops CI Pipeline , Linux GPU CI Pipeline , Linux GPU TensorRT CI Pipeline , Linux OpenVINO CI Pipeline , MacOS CI Pipeline , Windows CPU CI Pipeline , Windows GPU CI Pipeline , Windows GPU TensorRT CI Pipeline , Windows WebAssembly CI Pipelin

@azure-pipelines
Copy link

Azure Pipelines successfully started running 7 pipeline(s).

@hanbitmyths
Copy link
Contributor

/azp run onnxruntime-python-checks-ci-pipeline , orttraining-amd-gpu-ci-pipeline , orttraining-ortmodule-distributed , Linux CPU Minimal Build E2E CI Pipeline , Linux Nuphar CI Pipeline, MacOS NoContribops CI Pipeline , orttraining-distributed , orttraining-linux-ci-pipeline , orttraining-linux-gpu-ci-pipeline , orttraining-mac-ci-pipeline,

@hanbitmyths
Copy link
Contributor

/azp run orttraining-linux-gpu-ci-pipeline, Windows WebAssembly CI Pipeline

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

@azure-pipelines
Copy link

Azure Pipelines successfully started running 8 pipeline(s).

@hanbitmyths
Copy link
Contributor

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js/react_native/e2e/async-2.6.4 branch from 7b6f906 to 26e60ba Compare June 22, 2022 23:41
@hanbitmyths
Copy link
Contributor

/azp run Linux, CPU CI Pipeline , Linux CPU x64 NoContribops CI Pipeline , Linux GPU CI Pipeline , Linux GPU TensorRT CI Pipeline , Linux OpenVINO CI Pipeline , MacOS CI Pipeline , Windows CPU CI Pipeline , Windows GPU CI Pipeline , Windows GPU TensorRT CI Pipeline , Windows WebAssembly CI Pipeline

@hanbitmyths
Copy link
Contributor

/azp run onnxruntime-python-checks-ci-pipeline , orttraining-amd-gpu-ci-pipeline , orttraining-ortmodule-distributed , Linux CPU Minimal Build E2E CI Pipeline , Linux Nuphar CI Pipeline, MacOS NoContribops CI Pipeline , orttraining-distributed , orttraining-linux-ci-pipeline , orttraining-linux-gpu-ci-pipeline , orttraining-mac-ci-pipeline

@azure-pipelines
Copy link

Azure Pipelines successfully started running 7 pipeline(s).

@hanbitmyths
Copy link
Contributor

/azp run orttraining-linux-gpu-ci-pipeline, Windows WebAssembly CI Pipeline

@azure-pipelines
Copy link

Azure Pipelines successfully started running 8 pipeline(s).

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

@hanbitmyths
Copy link
Contributor

@dependabot rebase

Bumps [async](https://github.com/caolan/async) from 2.6.3 to 2.6.4.
- [Release notes](https://github.com/caolan/async/releases)
- [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md)
- [Commits](caolan/async@v2.6.3...v2.6.4)

---
updated-dependencies:
- dependency-name: async
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/js/react_native/e2e/async-2.6.4 branch from 26e60ba to 92bef17 Compare June 24, 2022 00:16
@hanbitmyths
Copy link
Contributor

/azp run Linux, CPU CI Pipeline , Linux CPU x64 NoContribops CI Pipeline , Linux GPU CI Pipeline , Linux GPU TensorRT CI Pipeline , Linux OpenVINO CI Pipeline , MacOS CI Pipeline , Windows CPU CI Pipeline , Windows GPU CI Pipeline , Windows GPU TensorRT CI Pipeline , Windows WebAssembly CI Pipeline

@hanbitmyths
Copy link
Contributor

/azp run onnxruntime-python-checks-ci-pipeline , orttraining-amd-gpu-ci-pipeline , orttraining-ortmodule-distributed , Linux CPU Minimal Build E2E CI Pipeline , Linux Nuphar CI Pipeline, MacOS NoContribops CI Pipeline , orttraining-distributed , orttraining-linux-ci-pipeline , orttraining-linux-gpu-ci-pipeline , orttraining-mac-ci-pipeline

@hanbitmyths
Copy link
Contributor

/azp run orttraining-linux-gpu-ci-pipeline, Windows WebAssembly CI Pipeline

@azure-pipelines
Copy link

Azure Pipelines successfully started running 7 pipeline(s).

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

@azure-pipelines
Copy link

Azure Pipelines successfully started running 8 pipeline(s).

@hanbitmyths
Copy link
Contributor

/azp run onnxruntime-binary-size-checks-ci-pipeline, ONNX Runtime Web CI Pipeline, Linux CPU CI Pipeline

@azure-pipelines
Copy link

Azure Pipelines successfully started running 3 pipeline(s).

@hanbitmyths hanbitmyths merged commit 68afa2d into master Jun 27, 2022
@hanbitmyths hanbitmyths deleted the dependabot/npm_and_yarn/js/react_native/e2e/async-2.6.4 branch June 27, 2022 17:30
RandySheriffH pushed a commit that referenced this pull request Aug 2, 2022
Bumps [async](https://github.com/caolan/async) from 2.6.3 to 2.6.4.
- [Release notes](https://github.com/caolan/async/releases)
- [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md)
- [Commits](caolan/async@v2.6.3...v2.6.4)

---
updated-dependencies:
- dependency-name: async
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
RandySheriffH added a commit that referenced this pull request Aug 3, 2022
* update package version

* Prevent unbounded growth of command allocator memory (#12114)

Prevent unbounded growth of command allocator memory

* Update supported ops md for NNAPI/CoreML EP (#12245)

* update supported ops md

* address pr comments

* address pr comments

* wording

* Change native folder name for java macos arm64 (#12335)

* Bump async from 2.6.3 to 2.6.4 in /js/react_native/e2e (#11280)

Bumps [async](https://github.com/caolan/async) from 2.6.3 to 2.6.4.
- [Release notes](https://github.com/caolan/async/releases)
- [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md)
- [Commits](caolan/async@v2.6.3...v2.6.4)

---
updated-dependencies:
- dependency-name: async
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* [js/rn] upgrade dependencies for e2e test (#11863)

* [js/rn] upgrade dependencies for e2e test

* use JDK11 only for gradle

* expand variable

* [js/rn] upgrade package react-native@^0.69.1 (#12155)

* [js/rn] upgrade package react-native@^0.69.1

* upgrade compile sdk to v31

* update ios version requirement

* update pod path for onnxruntime-react-native

* add missing build_java in Android testing stage. (#12187)

add missing build_java in testing

* Use specific Android NDK version in CI builds. (#12350)

Current builds use a NDK version that happens to be on the build machine. The build machine environment may change in ways that are outside of our control.
This change installs a specific version of NDK (the current LTS version 25.0.8775105) and uses it.

* Remove preview keyword from DirectML pacakge (#12368)

Remove preview keyword

Co-authored-by: Sumit Agarwal <[email protected]>

* Scope CreateFileMapping2 to valid API partitions (#12374)

* Fix TRT custom op issue (#12283)

* Pass schema registry on CreateModel.

* Fix ORT_MINIMAL_BUILD.

* Fix build issue.

* Manually add optimization flag for Android Release builds. (#12390)

With recent versions of NDK (since 23), the `-O` optimization level compile flag is not being passed when building in the "Release" configuration.
More details here: android/ndk#1740

Our "Release" Android builds have been built without the optimization flag since we upgraded from NDK 21.

This change is a workaround to manually add `-O3` for "Release" Android builds.

* resolve conflicts in tensorRT related changes

* Enable support of multi-level nested control flow ops model for TRT EP (#12147)

* Make multiple-level nested control flow op model work

* find correct input index

* find correct input index (cont.)

* enable nested layer unit tests for TRT EP

* add comment

* add Scan op to current workaround support of control flow op

Co-authored-by: Jeff Bloomfield <[email protected]>
Co-authored-by: Rachel Guo <[email protected]>
Co-authored-by: Changming Sun <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Yulong Wang <[email protected]>
Co-authored-by: Yi Zhang <[email protected]>
Co-authored-by: Edward Chen <[email protected]>
Co-authored-by: sumitsays <[email protected]>
Co-authored-by: Sumit Agarwal <[email protected]>
Co-authored-by: Justin Stoecker <[email protected]>
Co-authored-by: Yateng Hong <[email protected]>
Co-authored-by: Chi Lo <[email protected]>
siweic0 pushed a commit to siweic0/onnxruntime-web that referenced this pull request May 9, 2024
Bumps [async](https://github.com/caolan/async) from 2.6.3 to 2.6.4.
- [Release notes](https://github.com/caolan/async/releases)
- [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md)
- [Commits](caolan/async@v2.6.3...v2.6.4)

---
updated-dependencies:
- dependency-name: async
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants