BloombergGraphics / whatiscode

Paul Ford’s “What Is Code?”
http://www.bloomberg.com/whatiscode
Apache License 2.0
3.68k stars 261 forks source link

Bump debug, grunt-contrib-watch and grunt-usemin #164

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps debug to 4.0.1 and updates ancestor dependencies debug, grunt-contrib-watch and grunt-usemin. These dependencies need to be updated together.

Updates debug from 0.7.4 to 4.0.1

Release notes

Sourced from debug's releases.

4.0.1

This patch restores browserify functionality as well as keeping the intended functionality with Unpkg.com.

Patches

  • fix browserify and supply alternative unpkg entry point (closes #606): 99c95e3d54b07a918ad65bc148a2930ea8bfdd02

4.0.0

A long-awaited release to debug is available now: 4.0.0.

Due to the delay in release and the number of changes made (including bumping dependencies in order to mitigate vulnerabilities), it is highly recommended maintainers update to the latest package version and test thoroughly.

This release drops support for Node 4 and 5 in alignment with the Node.js LTS Release Schedule.


Major Changes

  • move to XO (closes #397): ba8a424d41e9dc6129e081ac3aa9715be6a45fbd
  • add Node.js 10, remove Node.js 4 (#583): 05b0ceb8856bc7b6bb0f2adc3de5cae3cea9c872

Minor Changes

  • bump vulnerable packages: 853853f9f588044d76df3daf1959ca56c5f341b7
  • Fix nwjs support (#569): 207a6a2d53507ec9dd57c94c46cc7d3dd272306d
  • add instance extends feature (#524): e43e5fed177b8698674748063f4ed1aaba1d59c8
  • Add TVMLKit support (#579): 02b9ea9fd7ec95c42de47da13b4b6bb8e50025d8

Patches

  • clean up builds: 3ca23316a470f6bc6e0d75d297179cfc19bbc763
  • remove needless command aliases in makefile: 9f4f8f59ba745166b0c014a61c76de5e73d4841a
  • no longer checking for BROWSER=1: 623c08ef73f8211278d5596c88041c65a2a58ee7
  • fix tests: 57cde56e43003f6b404d4b3d9d76b74aafaeeec8
  • clean up makefile: 62822f12668e8a0b1d1a4fd5a1c2fce1d8715da3
  • fix tests: 833b6f84c8f8dc5b6f13da38ab0ef8a8ff86c0c9
  • add .editorconfig: 2d2509e26bf6df1e1954267e3b1a1cb83973fb09
  • add yarn-error.log to .gitignore: 7e1d5d94f31b37b460fb8d88000ab7ed0be3597e
  • Improve usability of Windows notes w/ examples for prompts & npm script (#577): 1ad1e4a79ff36981c1972bb4e61f93c7d4ade68d
  • Drop usage of chrome.storage (or make the storage backend pluggable): 71d2aa77ff54c3c95a000bdead6b710b2a762c3f
  • Detect 'process' package: 225c66f7198d2995e8232f9486aa9e087dc2a469
  • Update ms to 2.1.1 (#539): 22f993216dcdcee07eb0601ea71a917e4925a30a
  • Update .npmignore (#527): a5ca7a20860e78a4ea47f80770c09c0c663bae1e
  • fix colors with supports-color@5: 285dfe10a5c06d4a86176b54bef2d7591eedaf40
  • Document enable() (#517): ab5083f68a7e4c1ab474ff06cd5995d706abf143
  • refactor to make the common code be a setup function (#507): 71169065b5262f9858ac78cc0b688c84a438f290
  • Simplify and improve: da51af8314436ab532c151583f7fd52b2ebf2a3e
  • use babel-ified distributed source for browsers: b3f8f8e683915ef4fae3a77cbcebc6c410e65a8c

Credits

Huge thanks to @​DanielRuf, @​EirikBirkeland, @​KyleStay, @​Qix-, @​abenhamdine, @​alexey-pelykh, @​DiegoRBaquero, @​febbraro, @​kwolfy, and @​TooTallNate for their help!

3.2.6

... (truncated)

Commits


Updates grunt-contrib-watch from 0.5.3 to 1.1.0

Changelog

Sourced from grunt-contrib-watch's changelog.

v1.1.0: date: 2018-05-12 changes: - Update to tiny-lr@1.1.1, lodash@4.17.10, async@2.6.0 v1.0.1: date: 2018-04-20 changes: - Update to gaze@1.1, lodash@4 v1.0.0: date: 2016-03-12 changes: - Updated tiny-lr, gaze, async and lodash dependencies. - Fix endless loop issue with atBegin/nospawn. - Expose hostname parameter of tiny-lr. - Support cwd.event to emit events relative to path. - Removed peerDependencies setting. v0.6.1: date: 2014-03-19 changes: - Fix for watch targets named "default". v0.6.0: date: 2014-03-11 changes: - Clear changed files after triggering live reload to ensure they're only triggered once. - 'cwd option now accepts separate settings for files and spawn.' - Fix to make interrupt work more than once. - Enable live reload over HTTPS. - Print newline after initial 'Waiting...'. - Remove deprecated grunt.util libs. - Add reload option to specify files other than Gruntfile files to reload. - Update to gaze@0.5.1. - Use a fork of tiny-lr (which has quiter operation, support for HTTPS and Windows path fixes). - Add livereloadOnError, which if set to false will not trigger live reload if there is an error.

Commits


Updates grunt-usemin from 2.6.2 to 3.1.1

Release notes

Sourced from grunt-usemin's releases.

3.1.1

Fixing breaking change: you can use both uglify or uglifyjs in usemin task.

3.1.0

SVG support: https://github.com/yeoman/grunt-usemin/commit/6119f90bde1c64eddfe1d2717ad98dead9f73768

Changes: https://github.com/yeoman/grunt-usemin/compare/v3.0.0...v3.1.0

3.0.0

Commits
Maintainer changes

This version was pushed to npm by arthurvr, a new releaser for grunt-usemin since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/BloombergGraphics/whatiscode/network/alerts).