Closed dependabot[bot] closed 2 years ago
@dependabot merge
On Sat, Feb 12, 2022, 07:37 dependabot[bot] @.***> wrote:
This automated pull request fixes a security vulnerability https://github.com/Terkwood/BreadAmp/security/dependabot/51 (moderate severity).
Learn more about Dependabot security updates https://docs.github.com/github/managing-security-vulnerabilities/configuring-dependabot-security-updates.
Bumps ajv https://github.com/ajv-validator/ajv from 6.12.2 to 6.12.6. Release notes
Sourced from ajv's releases https://github.com/ajv-validator/ajv/releases.
v6.12.6
Fix performance issue of "url" format. v6.12.5
Fix uri scheme validation (@ChALkeR https://github.com/ChALkeR). Fix boolean schemas with strictKeywords option (#1270 https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1270) v6.12.4
Fix: coercion of one-item arrays to scalar that should fail validation (failing example https://runkit.com/esp/5f3672ba2f6642001ae27411). v6.12.3
Pass schema object to processCode function Option for strictNumbers ( @issacgerges https://github.com/issacgerges, #1128 https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1128) Fixed vulnerability related to untrusted schemas (CVE-2020-15366 https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=CVE-2020-15366)
Commits
- fe59143 https://github.com/ajv-validator/ajv/commit/fe591439f34e24030f69df9eb8d91e6d037a3af7 6.12.6
- d580d3e https://github.com/ajv-validator/ajv/commit/d580d3e8ac6a467670d68d86e3a39fd661ac8c23 Merge pull request #1298 https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1298 from ajv-validator/fix-url
- fd36389 https://github.com/ajv-validator/ajv/commit/fd363896a8d6c5697b5da41f4d9a400a84efaf8e fix: regular expression for "url" format
- 490e34c https://github.com/ajv-validator/ajv/commit/490e34c4846064db5c962a77087e17078954c2f6 docs: link to v7-beta branch
- 9cd93a1 https://github.com/ajv-validator/ajv/commit/9cd93a1bdbdefd5a7ba3db5e123d20c84d1d1d0e docs: note about v7 in readme
- 877d286 https://github.com/ajv-validator/ajv/commit/877d286e7f145b1b2127da66c6800b071533f28f Merge pull request #1262 https://github-redirect.dependabot.com/ajv-validator/ajv/issues/1262 from b4h0-c4t/refactor-opt-object-type
- f1c8e45 https://github.com/ajv-validator/ajv/commit/f1c8e45b9cdff918be28becf03bf0b339321c398 6.12.5
- 764035e https://github.com/ajv-validator/ajv/commit/764035e201d7733b8d700d4a04dd079fef9f4d30 Merge branch 'ChALkeR-chalker/fix-comma'
- 3798160 https://github.com/ajv-validator/ajv/commit/37981602ce6d43313ae106644b372b021626a8af Merge branch 'chalker/fix-comma' of git://github.com/ChALkeR/ajv into ChALkeR...
- a3c7eba https://github.com/ajv-validator/ajv/commit/a3c7ebab222e4cce07b5e30ebcbb809da7f934e8 Merge branch 'refactor-opt-object-type' of github.com:b4h0-c4t/ajv into refac...
- Additional commits viewable in compare view https://github.com/ajv-validator/ajv/compare/v6.12.2...v6.12.6
[image: Dependabot compatibility score] https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page https://github.com/Terkwood/BreadAmp/network/alerts.
You can view, comment on, or merge this pull request online at:
https://github.com/Terkwood/BreadAmp/pull/14 Commit Summary
- 03e1ece https://github.com/Terkwood/BreadAmp/pull/14/commits/03e1ecef84aaf4a231ef4ddd338cc7ff0ce77be5 Bump ajv from 6.12.2 to 6.12.6 in /ui
File Changes
(1 file https://github.com/Terkwood/BreadAmp/pull/14/files)
- M ui/package-lock.json https://github.com/Terkwood/BreadAmp/pull/14/files#diff-86dd4842508e2d279ac0a1b9a660d6494b53ee7ccf321d641c0421cb15202fa6 (6)
Patch Links:
- https://github.com/Terkwood/BreadAmp/pull/14.patch
- https://github.com/Terkwood/BreadAmp/pull/14.diff
— Reply to this email directly, view it on GitHub https://github.com/Terkwood/BreadAmp/pull/14, or unsubscribe https://github.com/notifications/unsubscribe-auth/AJIPHCCXYFKMICJWBJITIH3U2ZH67ANCNFSM5OGYRIDQ . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.
You are receiving this because you are subscribed to this thread.Message ID: @.***>
Bumps ajv from 6.12.2 to 6.12.6.
Release notes
Sourced from ajv's releases.
Commits
fe59143
6.12.6d580d3e
Merge pull request #1298 from ajv-validator/fix-urlfd36389
fix: regular expression for "url" format490e34c
docs: link to v7-beta branch9cd93a1
docs: note about v7 in readme877d286
Merge pull request #1262 from b4h0-c4t/refactor-opt-object-typef1c8e45
6.12.5764035e
Merge branch 'ChALkeR-chalker/fix-comma'3798160
Merge branch 'chalker/fix-comma' of git://github.com/ChALkeR/ajv into ChALkeR...a3c7eba
Merge branch 'refactor-opt-object-type' of github.com:b4h0-c4t/ajv into refac...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Terkwood/BreadAmp/network/alerts).