Open dependabot[bot] opened 6 months ago
Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information
Processing PR updates...
Unable to locate .performanceTestingBot config file
By adding or modifying attributes of an object prototype, it is possible to create attributes that exist on every object, or replace critical attributes with malicious ones. This can be problematic if the software depends on existence or non-existence of certain attributes, or uses pre-defined attributes of object prototype (such as hasOwnProperty, toString or valueOf).
A race condition is a flaw that produces an unexpected result when the timing of actions impact other actions.
Thanks @dependabot[bot] for opening this PR!
For COLLABORATOR only :
To add labels, comment on the issue
/label add label1,label2,label3
To remove labels, comment on the issue
/label remove label1,label2,label3
Check out the playback for this Pull Request here.
PR Details of @dependabot[bot] in crypto-com-thaler : | OPEN | CLOSED | TOTAL |
---|---|---|---|
3 | 6 | 9 |
[!IMPORTANT]
Auto Review Skipped
Bot user detected.
To trigger a single review, invoke the
@coderabbitai review
command.You can disable this status message by setting the
reviews.review_status
tofalse
in the CodeRabbit configuration file.
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/ansi-colors@3.2.3, npm/ansi-regex@3.0.0, npm/ansi-styles@3.2.1, npm/anymatch@3.1.1, npm/argparse@1.0.10, npm/axios@0.21.1, npm/balanced-match@1.0.0, npm/binary-extensions@2.0.0, npm/brace-expansion@1.1.11, npm/camelcase@5.3.1, npm/chalk@2.4.2, npm/chokidar@3.3.0, npm/cliui@5.0.0, npm/color-convert@1.9.3, npm/color-name@1.1.3, npm/concat-map@0.0.1, npm/decamelize@1.2.0, npm/define-properties@1.1.3, npm/emoji-regex@7.0.3, npm/es-abstract@1.17.4, npm/es-to-primitive@1.2.1, npm/escape-string-regexp@1.0.5, npm/esprima@4.0.1, npm/find-up@3.0.0, npm/flat@4.1.0, npm/follow-redirects@1.15.1, npm/fsevents@2.1.2, npm/function-bind@1.1.1, npm/get-func-name@2.0.0, npm/glob-parent@5.1.0, npm/glob@7.1.3, npm/growl@1.10.5, npm/has-symbols@1.0.1, npm/has@1.0.3, npm/is-buffer@2.0.4, npm/is-callable@1.1.5, npm/is-date-object@1.0.2, npm/is-fullwidth-code-point@2.0.0, npm/is-glob@4.0.1, npm/is-regex@1.0.5, npm/is-symbol@1.0.3, npm/isexe@2.0.0, npm/js-yaml@3.13.1, npm/json-bigint@0.3.0, npm/locate-path@3.0.0, npm/log-symbols@3.0.0, npm/minimatch@3.0.4, npm/minimist@1.2.5, npm/mkdirp@0.5.3, npm/mocha@7.1.1, npm/node-environment-flags@1.0.6, npm/object-inspect@1.7.0, npm/object-keys@1.1.1, npm/object.assign@4.1.0, npm/object.getownpropertydescriptors@2.1.0, npm/p-limit@2.2.2, npm/p-locate@3.0.0, npm/p-try@2.2.0, npm/path-exists@3.0.0, npm/path-is-absolute@1.0.1, npm/pathval@1.1.0, npm/picomatch@2.2.1, npm/readdirp@3.2.0, npm/require-main-filename@2.0.0, npm/semver@5.7.1, npm/set-blocking@2.0.0, npm/sprintf-js@1.0.3, npm/string-width@2.1.1, npm/string.prototype.trimleft@2.1.1, npm/string.prototype.trimright@2.1.1, npm/strip-ansi@4.0.0, npm/strip-json-comments@2.0.1, npm/supports-color@6.0.0, npm/which-module@2.0.0, npm/which@1.3.1, npm/wide-align@1.1.3, npm/wrap-ansi@5.1.0, npm/y18n@4.0.0, npm/yargs-parser@13.1.2, npm/yargs-unparser@1.6.0, npm/yargs@13.3.2, pypi/mnemonic@0.19, pypi/mnemonic@0.19, pypi/more-itertools@8.1.0, pypi/more-itertools@8.1.0, pypi/packaging@20.0, pypi/packaging@20.0, pypi/pexpect@4.8.0, pypi/pexpect@4.8.0, pypi/pluggy@0.13.1, pypi/pluggy@0.13.1, pypi/ptyprocess@0.6.0, pypi/ptyprocess@0.6.0, pypi/py@1.11.0, pypi/py@1.11.0, pypi/pycparser@2.19, pypi/pyelftools@0.26, pypi/pyelftools@0.26, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pynacl@1.3.0, pypi/pyparsing@2.4.6, pypi/pyparsing@2.4.6, pypi/pyrsistent@0.15.7, pypi/pytest@5.3.2, pypi/pytest@5.3.2, pypi/python-decouple@3.3, pypi/requests@2.31.0, pypi/requests@2.31.0, pypi/scalecodec@0.9.36, pypi/scalecodec@0.9.36, pypi/scalecodec@1.3.0a5, pypi/scalecodec@1.3.0a5, pypi/six@1.14.0, pypi/six@1.14.0, pypi/supervisor@4.1.0, pypi/supervisor@4.1.0, pypi/termcolor@1.1.0, pypi/toml@0.10.0, pypi/toml@0.10.0, pypi/toml@0.10.0, pypi/urllib3@1.26.18, pypi/urllib3@1.26.18, pypi/wcwidth@0.1.8, pypi/wcwidth@0.1.8, pypi/zipp@1.0.0, pypi/zipp@1.0.0
Bumps the npm_and_yarn group with 7 updates in the /integration-tests/client-rpc directory:
0.21.1
0.28.0
0.3.0
1.0.0
3.0.0
3.0.1
4.1.0
5.0.2
7.1.1
10.4.0
2.0.0
2.0.2
1.1.0
1.1.1
Updates
axios
from 0.21.1 to 0.28.0Release notes
Sourced from axios's releases.
... (truncated)
Changelog
Sourced from axios's changelog.
... (truncated)
Commits
3b7635a
[Release] v0.28.0 (#6211)27c0076
feat(backport): added ability for paramsSerializer to handle function; (#6227)80c3d74
chore(ci): backported publish action; (#6224)2755df5
fix(security): fixed CVE-2023-45857 by backportingwithXSRFToken
option to ...880b42e
docs: Fix a typo in READMEc4bf0a4
Allow null indexes on formSerializer and paramsSerializer v0.x (#4961)1e2679f
fix: [Types] Type of header in AxiosRequestConfig / for Axios.create is incor...80b546c
fix: loosing request header (#4858) (#4871)6acb5ef
feat: brower platform add data protocol. (#4814)bbb2264
fix(typing): axios response headers can be undefined (#4813)Maintainer changes
This version was pushed to npm by jasonsaayman, a new releaser for axios since your current version.
Updates
json-bigint
from 0.3.0 to 1.0.0Commits
390482a
1.0.0f2d8f83
typo6ee392e
Merge pull request #37 from sidorares/fix/prototypec85a430
MAJOR: Add protoAction and constructorAction options4c2dbf4
build: add node 14b348ea3
fix assertion after chai upgrade725777c
add files section and bump depsebd1d91
add prettier config6c659f5
Merge pull request #36 from babyadoresorange/master1556563
update READMEUpdates
ansi-regex
from 3.0.0 to 3.0.1Commits
f545bdb
3.0.1c57d4c2
fix a few old XO issues for backport419250f
Fix potential ReDoS (#37)Updates
flat
from 4.1.0 to 5.0.2Commits
e5ffd66
Release 5.0.2fdb79d5
Update dependencies, refresh lockfile, format with standard.e52185d
Test against node 14 in CI.0189cb1
Avoid arrow function syntax.f25d3a1
Release 5.0.154cc7ad
use standard formatting779816e
drop dependencies2eea6d3
Bump lodash from 4.17.15 to 4.17.19a61a554
Bump acorn from 7.1.0 to 7.4.020ef0ef
Fix prototype pollution on unflattenMaintainer changes
This version was pushed to npm by timoxley, a new releaser for flat since your current version.
Updates
mocha
from 7.1.1 to 10.4.0Release notes
Sourced from mocha's releases.
... (truncated)
Changelog
Sourced from mocha's changelog.
... (truncated)
Commits
ffd9557
Release v10.4.07ac67f3
build(deps): bump the github-actions group with 2 updates (#5125)7a2781c
chore: activate dependabot for workflows (#5123)97dcbb2
fix: harden error handling inlib/cli/run.js
(#5074)6f3f45e
fix: xunit integration test (#5122)a5b5652
docs: fix documentation concerning glob expansion on UNIX (#4869)efbb147
feat: add file path to xunit reporter (#4985)a2e600d
fix: closes #5115 (#5116)3735873
feat: include.cause
stacks in the error stack traces (#4829)b88978d
chore: bump ESLint ecmaVersion to 2020 (#5104)Maintainer changes
This version was pushed to npm by voxpelli, a new releaser for mocha since your current version.
Updates
follow-redirects
from 1.15.1 to 1.15.6Commits
35a517c
Release version 1.15.6 of the npm package.c4f847f
Drop Proxy-Authorization across hosts.8526b4a
Use GitHub for disclosure.b1677ce
Release version 1.15.5 of the npm package.d8914f7
Preserve fragment in responseUrl.6585820
Release version 1.15.4 of the npm package.7a6567e
Disallow bracketed hostnames.05629af
Prefer native URL instead of deprecated url.parse.1cba8e8
Prefer native URL instead of legacy url.resolve.72bc2a4
Simplify _processResponse error handling.Updates
get-func-name
from 2.0.0 to 2.0.2Release notes
Sourced from get-func-name's releases.
Commits
Maintainer changes
This version was pushed to npm by keithamus, a new releaser for get-func-name since your current version.
Updates
glob-parent
from 5.1.0 to 5.1.2Release notes
Sourced from glob-parent's releases.
Changelog
Sourced from glob-parent's changelog.
Commits
eb2c439
chore: update changelog12bcb6c
chore: release 5.1.2f923116
fix: eliminate ReDoS (#36)0b014a7
chore: add JSDoc returns information (#33)2b24ebd
chore: generate initial changelog9b6e874
chore: release 5.1.1749c35e
ci: try wrapping the JOB_ID in a string5d39def
ci: attempt to switch to published coveralls0b5b37f
ci: put the npm step back in for only Windows473f5d8
ci: update azure build imagesUpdates
minimatch
from 3.0.4 to 5.0.1Changelog
Sourced from minimatch's changelog.
... (truncated)
Commits
9f49616
5.0.1cdc3188
don't load the whole path module just for the sepdfa4f22
test unix path so win32 has full coveragea000988
remove unused npmignore file0b2d3ba
mention fnmatch(3) in impl comparison8c3f5f4
skip tests on windows that rely on \ being a valid path charfc44f5f
5.0.09104d8d
Expect exclusively forward slash as path sep, same as node-glob58b72d3
fix(brace-expansion): ignore only blocks that begins with $048ada0
4.2.1Updates
debug
from 3.2.6 to 4.3.4Release notes
Sourced from debug's releases.
... (truncated)
Commits
da66c86
4.3.49b33412
replace deprecated String.prototype.substr() (#876)c0805cc
add section about configuring JS console to show debug messages (#866)043d3cd
4.3.34079aae
update license and more maintainership information19b36c0
update repository location + maintainership informationf851b00
adds README section regarding usage in child procs (#850)d177f2b
Remove accidental epizeuxise47f96d
4.3.21e9d38c
cache enabled status per-logger (#799)Maintainer changes
This version was pushed to npm by qix, a new releaser for debug since your current version.
Updates
pathval
from 1.1.0 to 1.1.1Release notes
Sourced from pathval's releases.
Commits
db6c3e3
chore: v1.1.17859e0e
Merge pull request #60 from deleonio/fix/vulnerability-prototype-pollution49ce1f4
style: correct rule in package.jsonc77b9d2
fix: prototype pollution vulnerability + working tests49031e4
chore: remove very old nodejs57730a9
chore: update deps and tool configurationa123018
Merge pull request #55 from chaijs/remove-lgtm07eb4a8
Delete MAINTAINERSa0147cd
Merge pull request #54 from astorije/patch-1aebb278
Center repo name on READMEMaintainer changes
This version was pushed to npm by chai, a new releaser for pathval since your current version.
Updates
y18n
from 4.0.0 to 5.0.8Release notes
Sourced from y18n's releases.
Changelog
Sourced from y18n's changelog.
... (truncated)
Commits
58a9a3c
chore: release 5.0.8 (#129)b1c215a
fix(deno): force modern release for Denoe73fb19
chore: release 5.0.7 (#123)d3f2560
fix(deno): force release for deno (#121)e9fda61
chore: release 5.0.6 (#118)6966fa9
fix(webpack): skip readFileSync if not defined (#117)c755582
docs: add entry for v4.0.1 (#114)2d4c56c
chore(deps): update dependency standardx to v6 (#110)b64ae70
chore: release 5.0.5 (#109)a9ac604
fix: address prototype pollution issue (#108)Maintainer changes
This version was pushed to npm by oss-bot, a new releaser for y18n since your current version.
You can trigger a rebase of this PR by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` w... _Description has been truncated_ > **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.