awslabs / aws-bootstrap-kit

Apache License 2.0
104 stars 23 forks source link

build(deps): bump parse-url and lerna in /cicd #125

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps parse-url to 8.1.0 and updates ancestor dependency lerna. These dependencies need to be updated together.

Updates parse-url from 7.0.2 to 8.1.0

Release notes

Sourced from parse-url's releases.

8.1.0

parse-url@8.1.0

  • fix: cjs to load normalize-url /cc #58
  • fix: Include index.d.ts in package.json /cc #63
  • feat: support custom SSH username /cc #60
  • feat: improve regex pattern /cc #59

Thanks to @​privatenumber and @​briancoit for their contributions! :cake:

8.0.0

parse-url 8.0.0

Breaking Changes

  • The resource property will not contain the port, but the host one will.
  • Throw an error if the input is invalid. Hence, file paths like /home/path/to/dir will only be valid if the file:// protocol is added (file://home/path/to/dir)
  • Throw an error if the input length exceeds the maximum length (parse.MAX_URL_LENGTH), by default 2048.

Fixes

Other changes

Commits
  • 4412976 Updated docs
  • ac17353 Merge branch 'patch-1' of github.com:briancoit/parse-url into new-version
  • 778a0a5 Merge branch 'support-custom-user' of github.com:privatenumber/parse-url into...
  • 0baab4f Merge branch 'improve-regex' of github.com:privatenumber/parse-url into new-v...
  • d1a4395 Merge branch 'fix-cjs' of github.com:privatenumber/parse-url into new-version
  • 9cacf38 :arrow_up: 8.1.0 :tada:
  • 9a78bd8 Merge pull request #61 from privatenumber/move-funding-yml
  • 1883136 Include index.d.ts in package
  • 92f899b chore: move FUNDING.yml out of workflows
  • 9500430 feat: support custom user in ssh url
  • Additional commits viewable in compare view


Updates lerna from 5.3.0 to 5.6.2

Release notes

Sourced from lerna's releases.

v5.6.2

5.6.2 (2022-10-09)

Bug Fixes

  • bootstrap: reject-cycles when using workspaces (#3168) (8a47a6d)
  • core: fix "cannot read property 'version' of undefined" for pnpm + independent versioning (#3358) (31e4c98)
  • core: replace "red" color with "brightBlue" on package's output prefix (#2774) (d7c1b87)
  • create: remove unused globby dep (#3360) (e873f0c)
  • npm-publish: Allows disabling of strict SSL checks (#2952) (eec3207)
  • run: always set env LERNA_PACKAGE_NAME environment variable (#3359) (012d31d)

v5.6.1

5.6.1 (2022-09-30)

Bug Fixes

  • add-caching: ensure lerna.json is configured automatically (9677cda)

v5.6.0

5.6.0 (2022-09-29)

Bug Fixes

  • run: only defer to Nx when targetDefaults are defined in nx.json (#3349) (51f80d9)

Features

v5.5.4

5.5.4 (2022-09-28)

Note: Version bump only for package lerna-monorepo

v5.5.3

5.5.3 (2022-09-28)

Bug Fixes

  • run: fully defer to Nx for dep detection when nx.json exists (#3345) (fef2ae6)

v5.5.2

... (truncated)

Changelog

Sourced from lerna's changelog.

5.6.2 (2022-10-09)

Note: Version bump only for package lerna

5.6.1 (2022-09-30)

Bug Fixes

  • add-caching: ensure lerna.json is configured automatically (9677cda)

5.6.0 (2022-09-29)

Features

5.5.4 (2022-09-28)

Note: Version bump only for package lerna

5.5.3 (2022-09-28)

Note: Version bump only for package lerna

5.5.2 (2022-09-20)

Note: Version bump only for package lerna

5.5.1 (2022-09-09)

Bug Fixes

  • run: exclude dependencies with --scope when nx.json is not present (#3316) (99a13a9)

5.5.0 (2022-08-31)

Features

Reverts

5.4.3 (2022-08-16)

Note: Version bump only for package lerna

... (truncated)

Commits


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/awslabs/aws-bootstrap-kit/network/alerts).