YaleSTC / reservations

Manage equipment loans & reservations. Who can borrow what, for how long?
yalestc.github.io/reservations
MIT License
139 stars 57 forks source link

Bump rubyzip and selenium-webdriver #1787

Closed dependabot[bot] closed 4 years ago

dependabot[bot] commented 5 years ago

Bumps rubyzip and selenium-webdriver. These dependencies needed to be updated together.

Updates rubyzip from 1.3.0 to 2.0.0

Release notes *Sourced from [rubyzip's releases](https://github.com/rubyzip/rubyzip/releases).* > ## v2.0.0 > Security > > - Default the `validate_entry_sizes` option to `true`, so that callers can trust an entry's reported size when using `extract` [#403](https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/403) > - This option defaulted to `false` in 1.3.0 for backward compatibility, but it now defaults to `true`. If you are using an older version of ruby and can't yet upgrade to 2.x, you can still use 1.3.0 and set the option to `true`. > > Tooling / Documentation > > - Remove test files from the gem to avoid problems with antivirus detections on the test files [#405](https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/405) / [#384](https://github-redirect.dependabot.com/rubyzip/rubyzip/issues/384) > - Drop support for unsupported ruby versions [#406](https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/406)
Changelog *Sourced from [rubyzip's changelog](https://github.com/rubyzip/rubyzip/blob/master/Changelog.md).* > # 2.0.0 (2019-09-25) > > Security > > - Default the `validate_entry_sizes` option to `true`, so that callers can trust an entry's reported size when using `extract` [#403](https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/403) > - This option defaulted to `false` in 1.3.0 for backward compatibility, but it now defaults to `true`. If you are using an older version of ruby and can't yet upgrade to 2.x, you can still use 1.3.0 and set the option to `true`. > > Tooling / Documentation > > - Remove test files from the gem to avoid problems with antivirus detections on the test files [#405](https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/405) / [#384](https://github-redirect.dependabot.com/rubyzip/rubyzip/issues/384) > - Drop support for unsupported ruby versions [#406](https://github-redirect.dependabot.com/rubyzip/rubyzip/pull/406)
Commits - [`2825898`](https://github.com/rubyzip/rubyzip/commit/2825898f69fbf1efe4e43452adae6ac5d074ec1c) Merge pull request [#408](https://github-redirect.dependabot.com/rubyzip/rubyzip/issues/408) from rubyzip/v2-0-0 - [`cb407b1`](https://github.com/rubyzip/rubyzip/commit/cb407b106541c345329a017d6eb34026cb372872) Bump version to 2.0.0 - [`e1d9af6`](https://github.com/rubyzip/rubyzip/commit/e1d9af6e46f7eb0d0b728958a57f7e28d60301a4) Merge pull request [#406](https://github-redirect.dependabot.com/rubyzip/rubyzip/issues/406) from rubyzip/bump-supported-ruby - [`3641a96`](https://github.com/rubyzip/rubyzip/commit/3641a963ea0c34275562250d7e67380c85fc2570) Merge pull request [#405](https://github-redirect.dependabot.com/rubyzip/rubyzip/issues/405) from rubyzip/remove-test-files - [`35446f4`](https://github.com/rubyzip/rubyzip/commit/35446f467b739d05790356ab86915de76f0120f1) Drop old ruby and JDK versions from CI - [`74d4bec`](https://github.com/rubyzip/rubyzip/commit/74d4bec371158c4c2a9fe965302dc9649c941a73) Remove test files from gem - See full diff in [compare view](https://github.com/rubyzip/rubyzip/compare/v1.3.0...v2.0.0)


Updates selenium-webdriver from 3.14.1 to 3.142.6

Release notes *Sourced from [selenium-webdriver's releases](https://github.com/SeleniumHQ/selenium/releases).* > ## Selenium 3.141.59 >
  • [nodejs] add pollTimeout argument to wait() in WebDriver class ([#6520](https://github-redirect.dependabot.com/SeleniumHQ/selenium/issues/6520)) :: jleyba
  • >
  • Copy static resources required by java tests into place :: Simon Stewart
  • >
  • Rework how we obtain command handlers :: Simon Stewart
  • >
  • Migrate router to use the new routes :: Simon Stewart
  • >
  • Migrate the Node to use the new routes :: Simon Stewart
  • >
  • Move the Distributor to the new routes :: Simon Stewart
  • >
  • Move the session map to the new routes :: Simon Stewart
  • >
  • Installing Requests in Python ([#6628](https://github-redirect.dependabot.com/SeleniumHQ/selenium/issues/6628)) :: Simon Stewart
  • >
  • Implement `WrapsElement` by `Select` element wrapper ([#6616](https://github-redirect.dependabot.com/SeleniumHQ/selenium/issues/6616)) :: Simon Stewart
  • >
  • [Grid] Adding a test to check that remoteHost is properly read and set. :: Diego Molina
  • >
  • [py] Fixing/tidying docstring. :: David Burns
  • >
  • Reveal the cunning plan of where to place java tracing :: Simon Stewart
  • >
  • Replace CompoundHandler with Routes :: Simon Stewart
  • >
  • Restored remoteHost support :: Diego Molina
  • >
  • Delete the old IDE :: Simon Stewart
  • >
  • Encourage people to access help over https :: Simon Stewart
  • >
  • Organise imports. No logical changes :: Simon Stewart
  • >
  • Fix mime-types of displayed content in help servlet :: Simon Stewart
  • >
  • Start binding distributed tracing into selenium :: Simon Stewart
  • >
  • Allow us to inject tracing information into headers :: Simon Stewart
  • >
  • Oops. Did not mean to check this in :: Simon Stewart
  • >
  • Add the distributed tracer to the grid :: Simon Stewart
  • >
  • Move tracing into the http client factory :: Simon Stewart
  • >
  • Wire tracing into the node :: Simon Stewart
  • >
  • Add the ability to autodetect opentracing implementations :: Simon Stewart
  • >
  • Continue wiring up distributed tracing for the new Grid :: Simon Stewart
  • >
  • Removing premature break statements in IE obscured element check :: Jim Evans
  • >
  • Adding support for strictFileInteractability capability in IE :: Jim Evans
  • >
  • Updating error message return from unserializable JavaScript result in IE :: Jim Evans
  • >
  • Updating IE prebuilts with latest binaries :: Jim Evans
  • >
  • Add a test to check for trace propagation :: Simon Stewart
  • >
  • Removing client-side references to tracing. For now :: Simon Stewart
  • >
  • delete unnecessary return value, nil :: Titus
  • >
  • Removing the scratch test. Again. Furrfu :: Simon Stewart
  • >
  • Avoid checking in temp tests again :: Simon Stewart
  • >
  • Ensure that the tracing library does not touch the old grid code :: Simon Stewart
  • >
  • Bump the java version and update changelogs :: Simon Stewart
  • > > ## Selenium 3.141.5 >
  • Also look in third party for crazy fun build files :: Simon Stewart
  • >
  • Updating csproj file to find legacy Firefox driver xpi in correct location :: Jim Evans
  • >
  • Updating .NET CHANGELOG for 3.141.0 release :: Jim Evans
  • >
  • Updating IE prebuilts for 3.141.0 release :: Jim Evans
  • >
  • Release Ruby bindings 3.141.0 :: Alex Rodionov
  • >
  • [py] Update change log for 3.141.0 :: AutomatedTester
  • >
  • Bump python version :: AutomatedTester
  • >
  • Remove deprecated AugmenterProviders :: Simon Stewart
  • >
  • I have no idea why buck-out was added as test root :: Simon Stewart
  • >
  • Remove sysout debugging :: Simon Stewart
  • > ... (truncated)
    Changelog *Sourced from [selenium-webdriver's changelog](https://github.com/SeleniumHQ/selenium/blob/master/rb/CHANGES).* > 3.142.6 (2019-10-04) > ==================== > > Ruby: > * Loosen ChildProcess dependency so that 3.0+ can be used (thanks [@​jaredbeck](https://github.com/jaredbeck)) > > 3.142.5 (2019-10-01) > ==================== > > Ruby: > * Loosen RubyZip dependency so that 1.3+ can be used (thanks [@​vtamara](https://github.com/vtamara)) > > 3.142.4 (2019-09-02) > ==================== > > Chrome: > * Added support for new command for getting logs in ChromeDriver 76+ > with W3C mode on > > 3.142.3 (2019-05-21) > ==================== > > Firefox: > * Fixed a regression when Firefox binary path was not sent to GeckoDriver > by default and browser could not be located (issue [#7219](https://github-redirect.dependabot.com/SeleniumHQ/selenium/issues/7219)) > > 3.142.2 (2019-05-11) > ==================== > > Chrome: > * Fixed an issue when getting/setting network conditions and sending CDP > commands didn't work with Grid (issue [#7174](https://github-redirect.dependabot.com/SeleniumHQ/selenium/issues/7174)) > > Safari: > * Fixed an issue when getting/setting permissions and attaching debugger > didn't work with Grid (issue [#7174](https://github-redirect.dependabot.com/SeleniumHQ/selenium/issues/7174)) > > 3.142.1 (2019-05-07) > ==================== > > Firefox: > * Fixed an issue when processing error in legacy driver would result > in NoMethodError (issue [#7178](https://github-redirect.dependabot.com/SeleniumHQ/selenium/issues/7178)) > > 3.142.0 (2019-04-24) > ==================== > > Ruby: > * Fixed an issue when services are not shutdown properly > > ... (truncated)
    Commits - See full diff in [compare view](https://github.com/SeleniumHQ/selenium/commits)


    Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


    Dependabot commands and options
    You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/YaleSTC/reservations/network/alerts).
    dependabot[bot] commented 4 years ago

    Superseded by #1803.