Open dependabot[bot] opened 1 year ago
New dependency changes detected. Learn more about Socket for GitHub βοΈ
π No new dependency issues detected in pull request
To ignore an alert, reply with a comment starting with @SocketSecurity ignore
followed by a space separated list of package-name@version
specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@*
or ignore all packages with @SocketSecurity ignore-all
β οΈ Please accept the latest app permissions to ensure bot commands work properly. Accept the new permissions here.
Issue | Status |
---|---|
Install scripts | β 0 issues |
Native code | β 0 issues |
Bin script shell injection | β 0 issues |
Unresolved require | β 0 issues |
Invalid package.json | β 0 issues |
HTTP dependency | β 0 issues |
Git dependency | β 0 issues |
Potential typo squat | β 0 issues |
Known Malware | β 0 issues |
Telemetry | β 0 issues |
Protestware/Troll package | β 0 issues |
π Modified Dependency Overview:
β Added Package | Capability Access | +/- Transitive Count |
Publisher |
---|---|---|---|
grunt-contrib-watch@1.1.0 | None | +11 |
shama |
β¬οΈ Updated Package | Version Diff | Added Capability Access | +/- Transitive Count |
Publisher |
---|---|---|---|---|
grunt-contrib-jshint@3.2.0 | 0.6.5...3.2.0 | None | +0/-1 |
vladikoff |
Bumps minimatch to 3.0.8 and updates ancestor dependencies minimatch, grunt-contrib-jshint and grunt-contrib-watch. These dependencies need to be updated together.
Updates
minimatch
from 0.2.14 to 3.0.8Changelog
Sourced from minimatch's changelog.
... (truncated)
Commits
782c264
3.0.86ade2da
fix: trim patterna6f52b0
3.0.7e4cd434
fix: treat nocase:true as always having magice6bbe1c
publishConfig for 3.05b7cd33
3.0.620b4b56
[fix] revert all breaking syntax changes2ff0388
document, expose, and test 'partial:true' option5dbd6a7
ci: tests and makeworkdbda065
full test coverage, adding tests, deleting dead codeMaintainer changes
This version was pushed to npm by isaacs, a new releaser for minimatch since your current version.
Updates
grunt-contrib-jshint
from 0.6.5 to 3.2.0Release notes
Sourced from grunt-contrib-jshint's releases.
... (truncated)
Changelog
Sourced from grunt-contrib-jshint's changelog.
... (truncated)
Commits
Maintainer changes
This version was pushed to npm by vladikoff, a new releaser for grunt-contrib-jshint since your current version.
Updates
grunt-contrib-watch
from 0.5.3 to 1.1.0Changelog
Sourced from grunt-contrib-watch's changelog.
Commits
3b7ddf4
v1.1.072b1214
Updating dependencies, async, lodash and tiny-lr5adb27c
Merge pull request #543 from digitalbazaar/master6ec71e9
v1.0.17d20933
Update copyright yeare3d19df
Update ci configsd117574
Updating ci configs99410a7
README.md: Fixed typos (#536)f07311b
Update tiny-lr dependency to 1.x7f8cf80
Add local grunt-cliDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/KOSASIH/data.gov/network/alerts).