Skip to content
This repository has been archived by the owner on May 5, 2024. It is now read-only.

Bump the minor_patch_dependencies group with 6 updates #7

Merged

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Nov 17, 2023

Bumps the minor_patch_dependencies group with 6 updates:

Package From To
adm-zip 0.5.9 0.5.10
chai 4.2.0 4.3.10
codecov 3.7.1 3.8.3
nyc 15.0.0 15.1.0
proxyquire 2.1.1 2.1.3
sinon-chai 3.3.0 3.7.0

Updates adm-zip from 0.5.9 to 0.5.10

Release notes

Sourced from adm-zip's releases.

v0.5.10

Add Unix mode attribute even when archive is created from Windows Fixed an issue where addLocalFolderAsync causes stack overflow when a lot of files are filtered Support to unzip symlinks Fix parameter initialization bug of extractAllToAsync Allow for custom stat or permissions value in addLocalFolder Various small fixes and tests

Commits

Updates chai from 4.2.0 to 4.3.10

Release notes

Sourced from chai's releases.

v4.3.10

This release simply bumps all dependencies to their latest non-breaking versions.

What's Changed

Full Changelog: chaijs/chai@v4.3.9...v4.3.10

v4.3.9

Upgrade dependencies.

This release upgrades dependencies to address CVE-2023-43646 where a large function name can cause "catastrophic backtracking" (aka ReDOS attack) which can cause the test suite to hang.

Full Changelog: chaijs/chai@v4.3.8...v4.3.9

v4.3.8

What's Changed

New Contributors

Full Changelog: chaijs/chai@v4.3.7...v4.3.8

v4.3.7

What's Changed

Full Changelog: chaijs/chai@v4.3.6...v4.3.7

v4.3.6

Update loupe to 2.3.1

v4.3.5

  • build chaijs fca5bb1
  • build(deps-dev): bump codecov from 3.1.0 to 3.7.1 (#1446) 747eb4e
  • fix package.json exports 022c2fa
  • fix: package.json - deprecation warning on exports field (#1400) 5276af6
  • feat: use chaijs/loupe for inspection (#1401) (#1407) c8a4e00

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by keithamus, a new releaser for chai since your current version.


Updates codecov from 3.7.1 to 3.8.3

Release notes

Sourced from codecov's releases.

v3.8.3

Fixes

  • #329 fix: Test if response has two lines

Dependencies

  • #306 Bump eslint-config-prettier from 7.2.0 to 8.3.0
  • #305 Bump eslint from 7.21.0 to 7.25.0
  • #302 Bump mock-fs from 4.13.0 to 4.14.0
  • #308 Bump lodash from 4.17.19 to 4.17.21
  • #309 Bump ignore-walk from 3.0.3 to 3.0.4
  • #310 Bump hosted-git-info from 2.8.8 to 2.8.9
  • #325 Bump prettier from 2.2.1 to 2.3.2
  • #326 Bump actions/setup-node from 2.1.5 to 2.2.0
  • #328 Bump lint-staged from 10.5.4 to 11.0.1
  • #330 Bump eslint from 7.25.0 to 7.31.0
  • #331 Bump ws from 7.3.1 to 7.5.3
  • #332 Bump urlgrey from 0.4.4 to 1.0.0
  • #334 Bump husky from 6.0.0 to 7.0.1
  • #333 Bump teeny-request from 7.0.1 to 7.1.1

v3.8.2

3.8.2

Fixes

  • #304 Add coverage-final.json as a possible coverage file during file lookup

v3.8.1

Fixes

  • #246 Revert "Bump teeny-request from 6.0.1 to 7.0.0"

v3.8.0

Features

  • #160 Add Github Actions support

Fixes

  • #173 Fix broken gcov command
  • #195 Update Node testing versions
  • #200 Remove flaky tests
  • #204 Create CHANGELOG and remove flaky v4 test
  • #208 Add license scan report and status
  • #220 Remove errant bitly

Dependencies

  • #189 Bump lint-staged from 10.0.7 to 10.2.11
  • #190 [Security] Bump handlebars from 4.5.3 to 4.7.6
  • #191 Bump prettier from 1.19.1 to 2.0.5
  • #192 Bump mock-fs from 4.10.4 to 4.12.0
  • #196 Bump teeny-request from 6.0.1 to 7.0.0

... (truncated)

Changelog

Sourced from codecov's changelog.

3.8.3

Fixes

  • #329 fix: Test if response has two lines

Dependencies

  • #306 Bump eslint-config-prettier from 7.2.0 to 8.3.0
  • #305 Bump eslint from 7.21.0 to 7.25.0
  • #302 Bump mock-fs from 4.13.0 to 4.14.0
  • #308 Bump lodash from 4.17.19 to 4.17.21
  • #309 Bump ignore-walk from 3.0.3 to 3.0.4
  • #310 Bump hosted-git-info from 2.8.8 to 2.8.9
  • #325 Bump prettier from 2.2.1 to 2.3.2
  • #326 Bump actions/setup-node from 2.1.5 to 2.2.0
  • #328 Bump lint-staged from 10.5.4 to 11.0.1
  • #330 Bump eslint from 7.25.0 to 7.31.0
  • #331 Bump ws from 7.3.1 to 7.5.3
  • #332 Bump urlgrey from 0.4.4 to 1.0.0
  • #334 Bump husky from 6.0.0 to 7.0.1
  • #333 Bump teeny-request from 7.0.1 to 7.1.1

3.8.2

Fixes

  • #304 Add coverage-final.json as a possible coverage file during file lookup

3.8.1

Fixes

  • #246 Revert "Bump teeny-request from 6.0.1 to 7.0.0"

3.8.0

Features

  • #160 Add Github Actions support

Fixes

  • #173 Fix broken gcov command
  • #195 Update Node testing versions
  • #200 Remove flaky tests
  • #204 Create CHANGELOG and remove flaky v4 test
  • #208 Add license scan report and status
  • #220 Remove errant bitly

Dependencies

  • #189 Bump lint-staged from 10.0.7 to 10.2.11
  • #190 [Security] Bump handlebars from 4.5.3 to 4.7.6
  • #191 Bump prettier from 1.19.1 to 2.0.5

... (truncated)

Commits
  • e22061b Merge pull request #335 from codecov/3.8.3
  • 981df8b 3.8.3
  • 135555c Merge pull request #333 from codecov/dependabot/npm_and_yarn/teeny-request-7.1.1
  • 65b53a3 Merge pull request #334 from codecov/dependabot/npm_and_yarn/husky-7.0.1
  • 6e4af4d Bump teeny-request from 7.0.1 to 7.1.1
  • 1149168 Merge pull request #332 from codecov/dependabot/npm_and_yarn/urlgrey-1.0.0
  • 883785c Merge pull request #331 from codecov/dependabot/npm_and_yarn/ws-7.5.3
  • 04d5ff7 Merge pull request #330 from codecov/dependabot/npm_and_yarn/eslint-7.31.0
  • e6c5bf4 Bump husky from 6.0.0 to 7.0.1
  • f781bc4 Bump ws from 7.3.1 to 7.5.3
  • Additional commits viewable in compare view

Updates nyc from 15.0.0 to 15.1.0

Changelog

Sourced from nyc's changelog.

15.1.0 (2020-06-01)

Features

  • experimental: Support using --all with node.js ESM (#1320) (992359a)

15.0.1 (2020-04-02)

Bug Fixes

Commits
  • de7baa4 chore(release): 15.1.0
  • 992359a feat(experimental): Support using --all with node.js ESM (#1320)
  • 086fd20 chore: Regenerate package-lock, update source-map-support test (#1314)
  • b20f751 chore: add bugs (used, e.g., by npmjs) (#1313)
  • 6898e88 chore: Fix CHANGELOG.md version header
  • d9a76d5 chore(release): 15.0.1
  • 3a577f0 fix: Ignore insignificant lines when coalesce text report (#1300)
  • df34c1c fix: Data merge concurrency limit to prevent OOM (#1293)
  • befbf08 chore: A test where nyc output help text to stderr was flaky (#1269)
  • 9260a70 docs: Remove nyc containing object in json config examples (#1276)
  • Additional commits viewable in compare view

Updates proxyquire from 2.1.1 to 2.1.3

Commits

Updates sinon-chai from 3.3.0 to 3.7.0

Release notes

Sourced from sinon-chai's releases.

3.7.0

https://github.com/domenic/sinon-chai/blob/master/CHANGELOG.md#370

3.6.0

https://github.com/domenic/sinon-chai/blob/master/CHANGELOG.md#360

3.5.0

https://github.com/domenic/sinon-chai/blob/master/CHANGELOG.md#350

3.4.0

https://github.com/domenic/sinon-chai/blob/master/CHANGELOG.md#340

Changelog

Sourced from sinon-chai's changelog.

3.7.0

  • No longer check for the max sinon version (#150)

3.6.0

  • Add support for sinon 10 (#149)

3.5.0

Features

  • Add support for sinon 9 (#147)

3.4.0

Features

  • Add support for sinon 8 (#143)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor_patch_dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [adm-zip](https://github.com/cthackers/adm-zip) | `0.5.9` | `0.5.10` |
| [chai](https://github.com/chaijs/chai) | `4.2.0` | `4.3.10` |
| [codecov](https://github.com/codecov/codecov-node) | `3.7.1` | `3.8.3` |
| [nyc](https://github.com/istanbuljs/nyc) | `15.0.0` | `15.1.0` |
| [proxyquire](https://github.com/thlorenz/proxyquire) | `2.1.1` | `2.1.3` |
| [sinon-chai](https://github.com/domenic/sinon-chai) | `3.3.0` | `3.7.0` |


Updates `adm-zip` from 0.5.9 to 0.5.10
- [Release notes](https://github.com/cthackers/adm-zip/releases)
- [Changelog](https://github.com/cthackers/adm-zip/blob/master/history.md)
- [Commits](https://github.com/cthackers/adm-zip/commits/v0.5.10)

Updates `chai` from 4.2.0 to 4.3.10
- [Release notes](https://github.com/chaijs/chai/releases)
- [Changelog](https://github.com/chaijs/chai/blob/4.x.x/History.md)
- [Commits](chaijs/chai@4.2.0...v4.3.10)

Updates `codecov` from 3.7.1 to 3.8.3
- [Release notes](https://github.com/codecov/codecov-node/releases)
- [Changelog](https://github.com/codecov/codecov-node/blob/master/CHANGELOG.md)
- [Commits](codecov/codecov-node@v3.7.1...v3.8.3)

Updates `nyc` from 15.0.0 to 15.1.0
- [Changelog](https://github.com/istanbuljs/nyc/blob/master/CHANGELOG.md)
- [Commits](istanbuljs/nyc@v15.0.0...v15.1.0)

Updates `proxyquire` from 2.1.1 to 2.1.3
- [Release notes](https://github.com/thlorenz/proxyquire/releases)
- [Commits](thlorenz/proxyquire@v2.1.1...v2.1.3)

Updates `sinon-chai` from 3.3.0 to 3.7.0
- [Release notes](https://github.com/domenic/sinon-chai/releases)
- [Changelog](https://github.com/domenic/sinon-chai/blob/master/CHANGELOG.md)
- [Commits](chaijs/sinon-chai@3.3.0...3.7.0)

---
updated-dependencies:
- dependency-name: adm-zip
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor_patch_dependencies
- dependency-name: chai
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor_patch_dependencies
- dependency-name: codecov
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor_patch_dependencies
- dependency-name: nyc
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor_patch_dependencies
- dependency-name: proxyquire
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor_patch_dependencies
- dependency-name: sinon-chai
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor_patch_dependencies
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Nov 17, 2023
@dependabot dependabot bot requested a review from danprueitt November 17, 2023 02:47
@danprueitt danprueitt merged commit ce180ec into master Nov 17, 2023
1 check passed
@danprueitt danprueitt deleted the dependabot/npm_and_yarn/minor_patch_dependencies-5a5da3f87c branch November 17, 2023 03:03
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant