Skip to content

build(deps): bump minimist and faucet - #398

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/minimist-and-faucet-1.2.8
Open

build(deps): bump minimist and faucet#398
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/minimist-and-faucet-1.2.8

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubFeb 28, 2023

Copy link
Copy Markdown

Bumps minimist to 1.2.8 and updates ancestor dependency faucet. These dependencies need to be updated together.

Updates minimist from 1.2.5 to 1.2.8

Changelog

Sourced from minimist's changelog.

v1.2.8 - 2023-02-09

Merged

Fixed

Commits

  • Merge tag 'v0.2.3' a026794
  • [eslint] fix indentation and whitespace 5368ca4
  • [eslint] fix indentation and whitespace e5f5067
  • [eslint] more cleanup 62fde7d
  • [eslint] more cleanup 36ac5d0
  • [meta] add auto-changelog73923d2
  • [actions] add reusable workflows d80727d
  • [eslint] add eslint; rules to enable later are warnings 48bc06a
  • [eslint] fix indentation 34b0f1c
  • [readme] rename and add badges 5df0fe4
  • [Dev Deps] switch from covert to nyca48b128
  • [Dev Deps] update covert, tape; remove unnecessary tapf0fb958
  • [meta] create FUNDING.yml; add funding in package.json 3639e0c
  • [meta] use npmignore to autogenerate an npmignore file be2e038
  • Only apps should have lockfiles 282b570
  • isConstructorOrProto adapted from PR ef9153f
  • [Dev Deps] update @ljharb/eslint-config, aud098873c
  • [Dev Deps] update @ljharb/eslint-config, aud3124ed3
  • [meta] add safe-publish-latest4b927de
  • [Tests] add aud in posttestb32d9bd
  • [meta] update repo URLs f9fdfc0
  • [actions] Avoid 0.6 tests due to build failures ba92fe6
  • [Dev Deps] update tape950eaa7
  • [Dev Deps] add missing npmignore dev dep 3226afa
  • Merge tag 'v0.2.2' 980d7ac

v1.2.7 - 2022-10-10

Commits

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by ljharb, a new releaser for minimist since your current version.


Updates faucet from 0.0.1 to 0.0.4

Changelog

Sourced from faucet's changelog.

v0.0.4 - 2023-02-04

Commits

  • [Deps] update array.prototype.foreach, array.prototype.join, array.prototype.map, array.prototype.push, array.prototype.slice, string.prototype.split, string.prototype.split, tape84d8f72
  • [actions] update checkout action 8e5332d
  • [Fix] downgrade tap-parser to v0.7.0 79c3ff2
  • [Dev Deps] update @ljharb/eslint-config, aud42d4d86
  • [Deps] update defined, minimist5ea8305

v0.0.3 - 2022-09-22

Commits

  • [Fix] use readable-stream to fix tests in node < 1 358d919
  • [Deps] update tap-parserfa1ee37
  • [Deps] update defined43a11c4

v0.0.2 - 2022-09-22

Merged

Commits

  • [eslint] add npm run lint4399c97
  • [meta] finish spaces -> tabs 8a62fc5
  • Trim too long assert messages to prevent line overflow f88d449
  • [actions] add reusable workflows 51df79a
  • [meta] add auto-changelog7a01dd6
  • [Robustness] use string.prototype.trim, array.prototype.foreach, array.prototype.pushedcea74
  • [meta] standardize license text 0d4aa82
  • [Robustness] revert non-array .push changes from edcea74 7694712
  • [Robustness] use array.prototype.join, array.prototype.map, string.prototype.split, array.prototype.slice555e2f6
  • [meta] add sideEffects flag, funding, FUNDING.ymla653c28
  • [Robustness] use safe-regex-test418c79e
  • [meta] use npmignore to autogenerate an npmignore file 5b18ec4
  • [Refactor] use npm-which to locate tape binary 0a9bd16
  • [Deps] update duplexer, sprintf, tap-parser6a8765c
  • [Deps] update tapef3ca01e
  • Only apps should have lockfiles d4559ca
  • [Fix] make tests pass 90a49a2
  • [meta] add safe-publish-latestd5d2f41
  • [breaking] add "exports" 2f159b1
  • [Refactor] use non-depreacted sprintf-js successor instead of sprintf1671ad5
  • [Deps] update minimist0994d21
Commits
  • 6f06608 v0.0.4
  • 79c3ff2 [Fix] downgrade tap-parser to v0.7.0
  • 84d8f72 [Deps] update array.prototype.foreach, array.prototype.join, `array.proto...
  • 42d4d86 [Dev Deps] update @ljharb/eslint-config, aud
  • 5ea8305 [Deps] update defined, minimist
  • 8e5332d [actions] update checkout action
  • ec6db3a v0.0.3
  • fa1ee37 [Deps] update tap-parser
  • 43a11c4 [Deps] update defined
  • 358d919 [Fix] use readable-stream to fix tests in node < 1
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by ljharb, a new releaser for faucet since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [minimist](https://github.com/minimistjs/minimist) to 1.2.8 and updates ancestor dependency [faucet](https://github.com/substack/faucet). These dependencies need to be updated together.
Updates `minimist` from 1.2.5 to 1.2.8
- [Release notes](https://github.com/minimistjs/minimist/releases)
- [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md)
- [Commits](minimistjs/minimist@v1.2.5...v1.2.8)
Updates `faucet` from 0.0.1 to 0.0.4
- [Release notes](https://github.com/substack/faucet/releases)
- [Changelog](https://github.com/ljharb/faucet/blob/main/CHANGELOG.md)
- [Commits](tape-testing/faucet@0.0.1...v0.0.4)
---
updated-dependencies:
- dependency-name: minimist
dependency-type: indirect
- dependency-name: faucet
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Feb 28, 2023
@guardrails

Copy link
Copy Markdown

⚠️ We detected 19 security issues in this pull request:

Mode: paranoid | Total findings: 19 | Considered vulnerability: 19

Vulnerable Libraries (19)
SeverityDetails
Mediumpkg:npm/node-fetch@3.2.9@3.2.9 (t) upgrade to: 3.2.10
Highpkg:npm/stylelint@13.13.1@13.13.1 (t) - no patch available
Mediumpkg:npm/postcss@7.0.36@7.0.36 (t) - no patch available
Highpkg:npm/json5@1.0.1@1.0.1 (t) upgrade to: 2.2.2
Highpkg:npm/ansi-regex@4.1.0@4.1.0 (t) upgrade to: 6.0.1,5.0.1,4.1.1,3.0.1
Highpkg:npm/cacheable-request@7.0.2@7.0.2 (t) upgrade to: 10.2.7
Highpkg:npm/css-what@2.1.3@2.1.3 (t) - no patch available
Highpkg:npm/nth-check@1.0.2@1.0.2 (t) upgrade to: 2.0.1
Lowpkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
Mediumpkg:npm/uglify-js@3.13.10@3.13.10 (t) - no patch available
Mediumpkg:npm/postcss@7.0.38@7.0.38 (t) - no patch available
N/Apkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
Highpkg:npm/json5@2.1.3@2.1.3 (t) upgrade to: 2.2.2
Highpkg:npm/ansi-regex@5.0.0@5.0.0 (t) upgrade to: 6.0.1,5.0.1,4.1.1,3.0.1
Highpkg:npm/marked@0.7.0@0.7.0 (t) upgrade to: 4.0.10
Highpkg:npm/ansi-regex@6.0.0@6.0.0 (t) upgrade to: 6.0.1,5.0.1,4.1.1,3.0.1
Highpkg:npm/minimatch@3.0.4@3.0.4 (t) upgrade to: 3.0.5
Highpkg:npm/trim-newlines@2.0.0@2.0.0 (t) upgrade to: 3.0.1,4.0.1
Highpkg:npm/prismjs@1.28.0@1.28.0 (t) - no patch available

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants