Open dependabot[bot] opened 5 months ago
Unable to locate .performanceTestingBot config file
Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information
Processing PR updates...
Thanks @dependabot[bot] for opening this PR!
For COLLABORATOR only :
To add labels, comment on the issue
/label add label1,label2,label3
To remove labels, comment on the issue
/label remove label1,label2,label3
Check out the playback for this Pull Request here.
[!IMPORTANT]
Review skipped
Bot user detected.
To trigger a single review, invoke the
@coderabbitai review
command.You can disable this status message by setting the
reviews.review_status
tofalse
in the CodeRabbit configuration file.
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media?
PR Details of @dependabot[bot] in osrm-backend : | OPEN | CLOSED | TOTAL |
---|---|---|---|
2 | 5 | 7 |
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/documentation@14.0.3 | filesystem, unsafe Transitive: environment, eval | +122 |
22.7 MB | tmcw |
npm/faucet@0.0.4 | Transitive: environment, eval, filesystem | +76 |
4.48 MB | ljharb |
🚮 Removed packages: npm/documentation@4.0.0, npm/faucet@0.0.1
:warning: We detected 2 security issues in this pull request:
👉 Go to the dashboard for detailed results.
📥 Happy? Share your feedback with us.
Use of vulnerable components will introduce weaknesses into the application. Components with published vulnerabilities will allow easy exploitation as resources will often be available to automate the process.
Bumps the npm_and_yarn group with 7 updates in the / directory:
7.18.13
7.24.7
4.2.1
4.2.3
4.2.1
5.0.1
4.0.0
14.0.3
0.0.5
1.2.8
0.0.1
0.0.4
6.1.11
6.2.1
Updates
@babel/traverse
from 7.18.13 to 7.24.7Release notes
Sourced from
@babel/traverse
's releases.... (truncated)
Changelog
Sourced from
@babel/traverse
's changelog.... (truncated)
Commits
bf1e9a3
v7.24.74463aa5
fix: incorrectconstantViolations
with destructuring (#16522)07bd000
ImprovegetBindingIdentifiers
(#16544)17a5502
[Babel 8] Removeextra.shorthand
(#16521)7934963
Usetype: module
in allpackage.json
s (#16535)9630250
v7.24.61f010df
Explicitly defineNodePath.prototype.*
(#16488)6e3539b
[babel 8] Publish.d.ts
files for every package (#16416)e37e64d
Use eslint v9 (#16479)3ff20b9
Statically generate boilerplate for bitfield accessors (#16482)Updates
browserify-sign
from 4.2.1 to 4.2.3Changelog
Sourced from browserify-sign's changelog.
Commits
bf2c3ec
v4.2.39247adf
[patch] widen support to 0.12f427270
[Deps] update `parse-asn187f3a35
[Dev Deps] updateaud
,npmignore
,tape
fb261ce
[Deps] updateelliptic
4d0ee49
[patch] drop minimum node support to v19e2bf12
[Deps] pinhash-base
to ~3.0, due to a breaking change168e16f
[Deps] pinelliptic
due to a breaking change37a4758
[actions] remove redundant finisher4af5a90
v4.2.2Maintainer changes
This version was pushed to npm by ljharb, a new releaser for browserify-sign since your current version.
Updates
yargs-parser
from 4.2.1 to 5.0.1Changelog
Sourced from yargs-parser's changelog.
Commits
eab6c03
chore: release 5.0.1 (#363)1c417bd
fix(security): address GHSA-p9pc-299p-vxgp (#362)e93a345
chore: mark release in commit history (#361)ee15863
chore: push new package version4774207
fix: back-porting prototype fixes for really old version (#271)2c95ba9
chore(release): 5.0.05755fa5
docs: use absolute path to yargs logo76cee1f
fix: environment variables should take precedence over config file (#81)Maintainer changes
This version was pushed to npm by oss-bot, a new releaser for yargs-parser since your current version.
Updates
documentation
from 4.0.0 to 14.0.3Release notes
Sourced from documentation's releases.
Changelog
Sourced from documentation's changelog.
Commits
8aae14b
chore(release): 14.0.39c42abb
build(deps): bump actions/setup-node from 3.6.0 to 3.8.0 (#1614)d4559be
build(deps-dev): bump mock-fs from 5.1.4 to 5.2.0 (#1601)e030a3f
Sort memberof (#1452)930edd2
Update USAGE.md (#1463)1cc2f98
fix: fix GFM markdown output (#1553)4600c97
Remove broken David badge on README (#1611)12cfa02
Update NODE_API.md (#1616)de30e89
Update membership.js (#1620)8fcbeae
Fix a few typos on CHANGELOG (#1610)Updates
minimist
from 0.0.5 to 1.2.8Changelog
Sourced from minimist's changelog.
... (truncated)
Commits
6901ee2
v1.2.8a026794
Merge tag 'v0.2.3'c0b2661
v0.2.363b8fee
[Fix] Fix long option followed by single dash (#17)72239e6
[Tests] Remove duplicate test (#12)34b0f1c
[eslint] fix indentation3226afa
[Dev Deps] add missingnpmignore
dev dep098873c
[Dev Deps] update@ljharb/eslint-config
,aud
9ec4d27
[Fix] Fix long option followed by single dashba92fe6
[actions] Avoid 0.6 tests due to build failuresMaintainer changes
This version was pushed to npm by ljharb, a new releaser for minimist since your current version.
Updates
faucet
from 0.0.1 to 0.0.4Changelog
Sourced from faucet's changelog.
Commits
6f06608
v0.0.479c3ff2
[Fix] downgradetap-parser
to v0.7.084d8f72
[Deps] updatearray.prototype.foreach
,array.prototype.join
, `array.proto...42d4d86
[Dev Deps] update@ljharb/eslint-config
,aud
5ea8305
[Deps] updatedefined
,minimist
8e5332d
[actions] update checkout actionec6db3a
v0.0.3fa1ee37
[Deps] updatetap-parser
43a11c4
[Deps] updatedefined
358d919
[Fix] usereadable-stream
to fix tests in node < 1Maintainer changes
This version was pushed to npm by ljharb, a new releaser for faucet since your current version.
Updates
parse-path
from 3.0.4 to 7.0.0Release notes
Sourced from parse-path's releases.
... (truncated)
Commits
c53b17e
Updated docsa0269b1
:arrow_up: 7.0.0 :tada:e3ee527
:arrow_up: 6.1.0 :tada:4bae19e
Add the parse_failed property.3d1525d
Updated docs31f7a33
Add the host property02995c6
Merge branch 'patch-1' of github.com:viceice/parse-path into new-versioncbb46e0
:arrow_up: 6.0.0 :tada:01b23dc
test: add test9032ebb
fix: use hostname instead of hostUpdates
parse-url
from 3.0.2 to 8.1.0Release notes
Sourced from parse-url's releases.
... (truncated)
Commits
4412976
Updated docsac17353
Merge branch 'patch-1' of github.com:briancoit/parse-url into new-version778a0a5
Merge branch 'support-custom-user' of github.com:privatenumber/parse-url into...0baab4f
Merge branch 'improve-regex' of github.com:privatenumber/parse-url into new-v...d1a4395
Merge branch 'fix-cjs' of github.com:privatenumber/parse-url into new-version9cacf38
:arrow_up: 8.1.0 :tada:9a78bd8
Merge pull request #61 from privatenumber/move-funding-yml1883136
Include index.d.ts in package92f899b
chore: move FUNDING.yml out of workflows9500430
feat: support custom user in ssh urlUpdates
tar
from 6.1.11 to 6.2.1Release notes
Sourced from tar's releases.
Changelog
Sourced from tar's changelog.