Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency updates for October 2024 #3388

Merged
merged 53 commits into from
Oct 8, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
53 commits
Select commit Hold shift + click to select a range
0e87c42
Bump node from 20.14.0-bookworm-slim to 20.17.0-bookworm-slim
dependabot[bot] Sep 1, 2024
eb4b16d
Bump ansible from 10.3.0 to 10.4.0 in /deploy
dependabot[bot] Sep 24, 2024
171c4c9
Bump serve-static and express
dependabot[bot] Sep 24, 2024
42a58c0
Bump Microsoft.NET.Test.Sdk from 17.11.0 to 17.11.1 in /Backend.Tests
dependabot[bot] Sep 24, 2024
16e8df0
Bump body-parser and express
dependabot[bot] Sep 24, 2024
1880e7a
Bump send and express
dependabot[bot] Sep 24, 2024
8a800b2
Bump dset from 3.1.3 to 3.1.4
dependabot[bot] Sep 24, 2024
49d5af5
Bump rollup from 2.79.1 to 2.79.2
dependabot[bot] Sep 27, 2024
35ba8da
Bump dotnet/sdk from 8.0.401-jammy to 8.0.402-jammy in /Backend
dependabot[bot] Oct 1, 2024
4d7d8a4
Bump kubernetes from 30.1.0 to 31.0.0 in /deploy
dependabot[bot] Oct 1, 2024
c695b75
Bump kubernetes from 30.1.0 to 31.0.0 in /maintenance
dependabot[bot] Oct 1, 2024
81f3a77
Bump pymongo from 4.8.0 to 4.10.0 in /maintenance
dependabot[bot] Oct 1, 2024
f9dc8ca
Bump MailKit from 4.7.1.1 to 4.8.0 in /Backend
dependabot[bot] Oct 1, 2024
ae8ba17
Bump Swashbuckle.AspNetCore from 6.7.3 to 6.8.1 in /Backend
dependabot[bot] Oct 1, 2024
bc41e3d
Bump actions/setup-node from 4.0.2 to 4.0.4
dependabot[bot] Oct 1, 2024
ce59247
Bump sillsdev/FieldWorks
dependabot[bot] Oct 1, 2024
937f2e8
Bump actions/setup-dotnet from 4.0.0 to 4.0.1
dependabot[bot] Oct 1, 2024
9c90597
Bump docker/setup-buildx-action from 3.3.0 to 3.6.1
dependabot[bot] Oct 1, 2024
f7e781a
Bump docker/setup-qemu-action from 3.0.0 to 3.2.0
dependabot[bot] Oct 1, 2024
4403e9d
Bump MailKit from 4.7.1.1 to 4.8.0 in /Backend.Tests
dependabot[bot] Oct 1, 2024
4fdf8bb
Bump Swashbuckle.AspNetCore from 6.7.3 to 6.8.1 in /Backend.Tests
dependabot[bot] Oct 1, 2024
7f676c2
Bump MongoDB.Driver from 2.28.0 to 2.29.0 in /Backend.Tests
dependabot[bot] Oct 1, 2024
a170fd5
Merge remote-tracking branch 'origin/dependabot/nuget/Backend.Tests/S…
imnasnainaec Oct 1, 2024
bce395b
Merge remote-tracking branch 'origin/dependabot/nuget/Backend.Tests/M…
imnasnainaec Oct 1, 2024
b91f706
Merge remote-tracking branch 'origin/dependabot/github_actions/docker…
imnasnainaec Oct 1, 2024
488b139
Merge remote-tracking branch 'origin/dependabot/github_actions/docker…
imnasnainaec Oct 1, 2024
9ceac8c
Merge remote-tracking branch 'origin/dependabot/github_actions/action…
imnasnainaec Oct 1, 2024
7f08e10
Merge remote-tracking branch 'origin/dependabot/github_actions/sillsd…
imnasnainaec Oct 1, 2024
51330d8
Merge remote-tracking branch 'origin/dependabot/github_actions/action…
imnasnainaec Oct 1, 2024
42def0b
Merge remote-tracking branch 'origin/dependabot/nuget/Backend/Swashbu…
imnasnainaec Oct 1, 2024
2f0adce
Merge remote-tracking branch 'origin/dependabot/nuget/Backend/MailKit…
imnasnainaec Oct 1, 2024
bda0b82
Merge remote-tracking branch 'origin/dependabot/pip/maintenance/pymon…
imnasnainaec Oct 1, 2024
a0a0c6e
Merge remote-tracking branch 'origin/dependabot/pip/maintenance/kuber…
imnasnainaec Oct 1, 2024
ba0a925
Merge remote-tracking branch 'origin/dependabot/pip/deploy/kubernetes…
imnasnainaec Oct 1, 2024
3a470c6
Merge remote-tracking branch 'origin/dependabot/docker/Backend/dotnet…
imnasnainaec Oct 1, 2024
7fab5bf
Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/rollup-2…
imnasnainaec Oct 1, 2024
89f1f63
Merge remote-tracking branch 'origin/dependabot/nuget/Backend.Tests/M…
imnasnainaec Oct 1, 2024
faeb05b
Merge remote-tracking branch 'origin/dependabot/pip/deploy/ansible-10…
imnasnainaec Oct 1, 2024
dc3da58
Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/multi-d6…
imnasnainaec Oct 1, 2024
707a4e8
Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/multi-94…
imnasnainaec Oct 1, 2024
f16cc12
Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/multi-cf…
imnasnainaec Oct 1, 2024
d513d6c
Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/dset-3.1…
imnasnainaec Oct 1, 2024
2c54835
Merge remote-tracking branch 'origin/dependabot/docker/node-20.17.0-b…
imnasnainaec Oct 1, 2024
9f026c7
Update license reports
imnasnainaec Oct 1, 2024
2eea49f
Bump send and express
dependabot[bot] Oct 7, 2024
a64008b
Bump body-parser and express
dependabot[bot] Oct 7, 2024
0c21344
Bump dset from 3.1.3 to 3.1.4
dependabot[bot] Oct 7, 2024
8b4a623
Merge branch 'master' into dependabot-2024-10
imnasnainaec Oct 7, 2024
637b0f2
Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/multi-94…
imnasnainaec Oct 7, 2024
849551a
Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/multi-cf…
imnasnainaec Oct 7, 2024
7eee32a
Merge remote-tracking branch 'origin/dependabot/npm_and_yarn/dset-3.1…
imnasnainaec Oct 7, 2024
480bd5d
Merge branch 'master' into dependabot-2024-10
imnasnainaec Oct 7, 2024
2190a84
Merge branch 'master' into dependabot-2024-10
imnasnainaec Oct 8, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/backend.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ jobs:
objects.githubusercontent.com:443
- uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- name: Setup dotnet
uses: actions/setup-dotnet@4d6c8fcf3c8f7a60068d26b594648e99df24cee3 # v4.0.0
uses: actions/setup-dotnet@6bd8b7f7774af54e05809fcc5431931b3eb1ddee # v4.0.1
with:
dotnet-version: ${{ matrix.dotnet }}
- name: Install ffmpeg
Expand Down Expand Up @@ -128,7 +128,7 @@ jobs:
# Manually install .NET to work around:
# https://github.com/github/codeql-action/issues/757
- name: Setup .NET
uses: actions/setup-dotnet@4d6c8fcf3c8f7a60068d26b594648e99df24cee3 # v4.0.0
uses: actions/setup-dotnet@6bd8b7f7774af54e05809fcc5431931b3eb1ddee # v4.0.1
with:
dotnet-version: "8.0.x"
- name: Initialize CodeQL
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/combine_deploy_image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,9 +38,9 @@ jobs:
security.ubuntu.com:80
sts.us-east-1.amazonaws.com:443
- name: Set up QEMU
uses: docker/setup-qemu-action@68827325e0b33c7199eb31dd4e31fbe9023e06e3 # v3.0.0
uses: docker/setup-qemu-action@49b3bc8e6bdd4a60e6116a5414239cba5943d3cf # v3.2.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
uses: docker/setup-buildx-action@988b5a0280414f521da01fcc63a27aeeb4b104db # v3.6.1
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@e3dd6a429d7300a6a4c196c26e071d42e0343502 # v4.0.2
with:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/commit_message_check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,4 +10,4 @@ permissions: # added using https://github.com/step-security/secure-workflows

jobs:
commit-message-lint:
uses: sillsdev/FieldWorks/.github/workflows/CommitMessage.yml@9972c2aa3ad9fa768bd82714208152c4b6ce6b2c
uses: sillsdev/FieldWorks/.github/workflows/CommitMessage.yml@ba50e637df9593a2a972b29bf670226e89c0a21b
4 changes: 2 additions & 2 deletions .github/workflows/frontend.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ jobs:
- name: Checkout repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4
with:
node-version: ${{ matrix.node-version }}
- run: npm ci
Expand Down Expand Up @@ -60,7 +60,7 @@ jobs:
- name: Checkout repository
uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7
- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
uses: actions/setup-node@0a44ba7841725637a19e28fa30b79a866c81b0a6 # v4.0.4
with:
node-version: ${{ matrix.node-version }}
- run: npm ci
Expand Down
2 changes: 1 addition & 1 deletion Backend.Tests/Backend.Tests.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
<NoWarn>$(NoWarn);CA1305;CA1859;CS1591</NoWarn>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="17.11.0" />
<PackageReference Include="Microsoft.NET.Test.Sdk" Version="17.11.1" />
<PackageReference Include="NUnit" Version="4.2.2" />
<PackageReference Include="NUnit3TestAdapter" Version="4.6.0" />
<PackageReference Include="coverlet.collector" Version="6.0.2"/>
Expand Down
6 changes: 3 additions & 3 deletions Backend/BackendFramework.csproj
Original file line number Diff line number Diff line change
Expand Up @@ -16,9 +16,9 @@
<PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="8.0.3" />
<PackageReference Include="Microsoft.IdentityModel.Tokens" Version="7.5.1" />
<PackageReference Include="System.IdentityModel.Tokens.Jwt" Version="7.5.1" />
<PackageReference Include="MailKit" Version="4.7.1.1" />
<PackageReference Include="MongoDB.Driver" Version="2.28.0" />
<PackageReference Include="Swashbuckle.AspNetCore" Version="6.7.3" />
<PackageReference Include="MailKit" Version="4.8.0" />
<PackageReference Include="MongoDB.Driver" Version="2.29.0" />
<PackageReference Include="Swashbuckle.AspNetCore" Version="6.8.1" />
<PackageReference Include="Xabe.FFmpeg" Version="5.2.6"/>

<!-- SIL Maintained Dependencies. -->
Expand Down
2 changes: 1 addition & 1 deletion Backend/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
############################################################

# Docker multi-stage build
FROM mcr.microsoft.com/dotnet/sdk:8.0.401-jammy AS builder
FROM mcr.microsoft.com/dotnet/sdk:8.0.402-jammy AS builder
WORKDIR /app

# Copy csproj and restore (fetch dependencies) as distinct layers.
Expand Down
8 changes: 5 additions & 3 deletions deploy/requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4,9 +4,9 @@
#
# pip-compile requirements.in
#
ansible==10.3.0
ansible==10.4.0
# via -r requirements.in
ansible-core==2.17.3
ansible-core==2.17.4
# via ansible
cachetools==5.5.0
# via google-auth
Expand All @@ -22,6 +22,8 @@ cryptography==43.0.1
# via
# ansible-core
# pyopenssl
durationpy==0.8
# via kubernetes
google-auth==2.34.0
# via kubernetes
idna==3.8
Expand All @@ -33,7 +35,7 @@ jinja2==3.1.4
# jinja2-base64-filters
jinja2-base64-filters==0.1.4
# via -r requirements.in
kubernetes==30.1.0
kubernetes==31.0.0
# via -r requirements.in
markupsafe==2.1.5
# via jinja2
Expand Down
2 changes: 1 addition & 1 deletion docs/user_guide/assets/licenses/frontend_licenses.txt
Original file line number Diff line number Diff line change
Expand Up @@ -41476,7 +41476,7 @@ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

dset 3.1.3
dset 3.1.4
MIT
The MIT License (MIT)

Expand Down
6 changes: 4 additions & 2 deletions maintenance/requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -18,13 +18,15 @@ cryptography==43.0.1
# via pyopenssl
dnspython==2.6.1
# via pymongo
durationpy==0.8
# via kubernetes
google-auth==2.34.0
# via kubernetes
humanfriendly==10.0
# via -r requirements.in
idna==3.8
# via requests
kubernetes==30.1.0
kubernetes==31.0.0
# via -r requirements.in
oauthlib==3.2.2
# via
Expand All @@ -38,7 +40,7 @@ pyasn1-modules==0.4.0
# via google-auth
pycparser==2.22
# via cffi
pymongo==4.8.0
pymongo==4.10.0
# via -r requirements.in
pyopenssl==24.2.1
# via -r requirements.in
Expand Down
106 changes: 59 additions & 47 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading