NodeSecure / cli

JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.
MIT License
367 stars 39 forks source link

chore(deps): bump the nodesecure-dependencies group with 2 updates #408

Closed dependabot[bot] closed 3 months ago

dependabot[bot] commented 3 months ago

Bumps the nodesecure-dependencies group with 2 updates: @nodesecure/rc and @nodesecure/scanner.

Updates @nodesecure/rc from 2.1.0 to 3.0.0

Release notes

Sourced from @​nodesecure/rc's releases.

v3.0.0

What's Changed

Full Changelog: https://github.com/NodeSecure/rc/compare/v2.1.0...v3.0.0

Commits
  • e16f591 3.0.0
  • d5fcb58 docs: blockquote, avoid scroll & add defs links (#248)
  • 25ecd7f refactor: migrate to @​openally/config (#247)
  • 22100e5 Merge pull request #246 from NodeSecure/remove-lock
  • 9529f10 chore: update dependencies
  • 5f2e10b chore: update to eslint v9
  • 44b2c28 chore: remove package-lock.json
  • 41801d0 chore(deps): bump fast-xml-parser from 4.2.7 to 4.4.1 (#245)
  • 87a4282 chore(deps-dev): bump the development-dependencies group with 3 updates (#242)
  • e701f5f chore(deps-dev): bump @​types/node in the development-dependencies group (#238)
  • Additional commits viewable in compare view


Updates @nodesecure/scanner from 5.3.0 to 6.0.1

Release notes

Sourced from @​nodesecure/scanner's releases.

v6.0.1

What's Changed

Full Changelog: https://github.com/NodeSecure/scanner/compare/scanner-v6.0.0...scanner-v6.0.1

v6.0.0

What's Changed

... (truncated)

Commits
  • 4a540d4 chore(scanner): v6.0.1
  • b00fd51 chore(deps): bump the github-actions group with 5 updates (#286)
  • 881635e fix(scanner): add missing @​nodesecure/contact (#285)
  • d35d228 chore(scanner): v6.0.0
  • e47733c Merge pull request #283 from NodeSecure/npm-types-v1.1.0
  • d306530 chore: update npm-types version for all workspaces
  • f41c9e7 chore(npm-types): v1.1.0
  • a4e2939 feat: implement @​nodesecure/rc to highlight contacts (#282)
  • 494e728 refactor(compare): migrate to V6 & fix some TS issues (#281)
  • 7a0a49f chore(deps-dev): bump @​types/node in the development-dependencies group (#279)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
dependabot[bot] commented 3 months ago

Looks like these dependencies are no longer updatable, so this is no longer needed.