Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update all non-major dependencies #204

Merged
merged 2 commits into from
Mar 14, 2024

Conversation

open-turo-bot
Copy link
Contributor

@open-turo-bot open-turo-bot commented Feb 1, 2024

This PR contains the following updates:

Package Type Update Change
@babel/eslint-parser (source) devDependencies patch 7.23.9 -> 7.23.10
alessandrojcm/commitlint-pre-commit-hook repository minor v9.11.0 -> v9.13.0
eslint (source) devDependencies minor 8.56.0 -> 8.57.0
nock devDependencies patch 13.5.1 -> 13.5.4
node patch 20.11.0 -> 20.11.1
rhysd/actionlint repository patch v1.6.26 -> v1.6.27
semver dependencies minor 7.5.4 -> 7.6.0

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

babel/babel (@​babel/eslint-parser)

v7.23.10

Compare Source

🐛 Bug Fix
alessandrojcm/commitlint-pre-commit-hook (alessandrojcm/commitlint-pre-commit-hook)

v9.13.0

Compare Source

Features
  • bump the commitlint group with 2 updates (61f9e97)
  • bump the commitlint group with 2 updates (28ca409)
  • converted to ESM (a203e19)

v9.12.0

Compare Source

Features
  • bump the commitlint group with 2 updates (cf4cb1e)
  • bump the commitlint group with 2 updates (076334a)
  • bump the commitlint group with 2 updates (0e51133)
  • bump the commitlint group with 2 updates (7075f07)
eslint/eslint (eslint)

v8.57.0

Compare Source

Features

  • 1120b9b feat: Add loadESLint() API method for v8 (#​18098) (Nicholas C. Zakas)
  • dca7d0f feat: Enable eslint.config.mjs and eslint.config.cjs (#​18066) (Nitin Kumar)

Bug Fixes

  • 2196d97 fix: handle absolute file paths in FlatRuleTester (#​18064) (Nitin Kumar)
  • 69dd1d1 fix: Ensure config keys are printed for config errors (#​18067) (Nitin Kumar)
  • 9852a31 fix: deep merge behavior in flat config (#​18065) (Nitin Kumar)
  • 4c7e9b0 fix: allow circular references in config (#​18056) (Milos Djermanovic)

Documentation

Chores

nock/nock (nock)

v13.5.4

Compare Source

Bug Fixes

v13.5.3

Compare Source

Bug Fixes

v13.5.2

Compare Source

Bug Fixes
  • remove duplicates from activeMocks() and pendingMocks() (#​2356) (7e957b3)
nodejs/node (node)

v20.11.1: 2024-02-14, Version 20.11.1 'Iron' (LTS), @​RafaelGSS prepared by @​marco-ippolito

Compare Source

Notable changes

This is a security release.

Notable changes
  • CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
  • CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
  • CVE-2024-21896 - Path traversal by monkey-patching Buffer internals- (High)
  • CVE-2024-22017 - setuid() does not drop all privileges due to io_uring - (High)
  • CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
  • CVE-2024-21891 - Multiple permission model bypasses due to improper path traversal sequence sanitization - (Medium)
  • CVE-2024-21890 - Improper handling of wildcards in --allow-fs-read and --allow-fs-write (Medium)
  • CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)
  • undici version 5.28.3
  • libuv version 1.48.0
  • OpenSSL version 3.0.13+quic1
Commits
rhysd/actionlint (rhysd/actionlint)

v1.6.27

Compare Source

  • Add macOS 14 runner labels for Apple Silicon support. The following labels are added. (thanks @​harryzcy, #​392)
    • macos-14
    • macos-14-xlarge
    • macos-14-large
  • Remove ubuntu-18.04 runner label from runners list since it is no longer supported. (#​363)
  • Allow glob patterns in self-hosted-runner.labels configuration. For example, the following configuration defines any runner labels prefixed with private-linux-. (thanks @​kishaningithub, #​378)
    self-hosted-runner:
        labels:
          - private-linux-*
  • Fix a race condition bug when -format option is used for linting multiple workflow files. Thanks @​ReinAchten-TomTom for your help on the investigation. (#​370)
  • Fix a race condition due to conflicts between some goroutine which starts to run shellcheck process and other goroutine which starts to wait until all processes finish.
  • The popular actions data set was updated to the latest and the following actions were newly added. (thanks @​jmarshall, #​380)
    • google-github-actions/auth
    • google-github-actions/get-secretmanager-secrets
    • google-github-actions/setup-gcloud
    • google-github-actions/upload-cloud-storage
    • pulumi/actions
    • pypa/gh-action-pypi-publish
  • Add support for larger runner labels. The following labels are added. (thanks @​therealdwright, #​371)
    • windows-latest-8-cores
    • ubuntu-latest-4-cores
    • ubuntu-latest-8-cores
    • ubuntu-latest-16-cores
  • The following WebHook types are supported for pull_request event.
    • enqueued
    • dequeued
    • milestoned
    • demilestoned
  • Explain how to control shellckeck behavior in the shellcheck rule document. Use SHELLCHECK_OPTS environment variable to pass arguments to shellcheck. See the shellcheck's official document for more details.
npm/node-semver (semver)

v7.6.0

Compare Source

Features
Chores

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@open-turo-bot open-turo-bot requested a review from a team as a code owner February 1, 2024 00:23
@open-turo-bot open-turo-bot force-pushed the c/renovate_all-minor-patch branch from 552bc94 to eb5f57d Compare February 6, 2024 00:22
@open-turo-bot open-turo-bot changed the title chore(deps): update dependency @babel/eslint-parser to v7.23.10 chore(deps): update all non-major dependencies Feb 6, 2024
Copy link

github-actions bot commented Feb 6, 2024

Changes need to be built and committed to ./dist.

In your local repo, run:

npm run prepare
git commit -a --amend --no-edit
git push --force-with-lease

This will add those changes to your last commit, and get them pushed to the remote.

Changes need to be built and committed to ./dist.

In your local repo, run:

npm run prepare
git commit -a --amend --no-edit
git push --force-with-lease

This will add those changes to your last commit, and get them pushed to the remote.

Changes need to be built and committed to ./dist.

In your local repo, run:

npm run prepare
git commit -a --amend --no-edit
git push --force-with-lease

This will add those changes to your last commit, and get them pushed to the remote.

Changes need to be built and committed to ./dist.

In your local repo, run:

npm run prepare
git commit -a --amend --no-edit
git push --force-with-lease

This will add those changes to your last commit, and get them pushed to the remote.

Changes need to be built and committed to ./dist.

In your local repo, run:

npm run prepare
git commit -a --amend --no-edit
git push --force-with-lease

This will add those changes to your last commit, and get them pushed to the remote.

Changes need to be built and committed to ./dist.

In your local repo, run:

npm run prepare
git commit -a --amend --no-edit
git push --force-with-lease

This will add those changes to your last commit, and get them pushed to the remote.

Changes need to be built and committed to ./dist.

In your local repo, run:

npm run prepare
git commit -a --amend --no-edit
git push --force-with-lease

This will add those changes to your last commit, and get them pushed to the remote.

@open-turo-bot open-turo-bot force-pushed the c/renovate_all-minor-patch branch 2 times, most recently from c72f3a7 to b6719de Compare February 18, 2024 00:24
@open-turo-bot open-turo-bot force-pushed the c/renovate_all-minor-patch branch 3 times, most recently from c3a37f0 to 0a448d3 Compare February 27, 2024 00:23
@open-turo-bot open-turo-bot force-pushed the c/renovate_all-minor-patch branch from 0a448d3 to 8d6013c Compare March 2, 2024 00:22
@tagoro9 tagoro9 force-pushed the c/renovate_all-minor-patch branch from 916cede to db092c2 Compare March 14, 2024 22:07
Copy link

Release notes preview

No new release will be created.

If you are expecting a release, you will need to either fix a bug or add a feature.
Chores, CI, docs, refactoring, style and other changes will not trigger a release.

@tagoro9 tagoro9 merged commit 7cb2a79 into main Mar 14, 2024
8 checks passed
@tagoro9 tagoro9 deleted the c/renovate_all-minor-patch branch March 14, 2024 22:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants