bcgov / ag-pssg-sdlc

Ministry of Attorney General, Ministry of Public Safety and Solicitor General Software Development Life Cycle.
Apache License 2.0
2 stars 0 forks source link

Bump loader-utils, react-scripts and react-styleguidist in /frontend-old #197

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps loader-utils to 2.0.4 and updates ancestor dependencies loader-utils, react-scripts and react-styleguidist. These dependencies need to be updated together.

Updates loader-utils from 1.4.0 to 2.0.4

Release notes

Sourced from loader-utils's releases.

v2.0.4

2.0.4 (2022-11-11)

Bug Fixes

v2.0.3

2.0.3 (2022-10-20)

Bug Fixes

  • security: prototype pollution exploit (#217) (a93cf6f)

v2.0.2

2.0.2 (2021-11-04)

Bug Fixes

  • base64 generation and unicode characters (#197) (8c2d24e)

v2.0.1

2.0.1 (2021-10-29)

Bug Fixes

v2.0.0

2.0.0 (2020-03-17)

⚠ BREAKING CHANGES

  • minimum required Node.js version is 8.9.0 (#166) (c937e8c)
  • the getOptions method returns empty object on empty query (#167) (b595cfb)
  • Use md4 by default

v1.4.2

1.4.2 (2022-11-11)

Bug Fixes

... (truncated)

Changelog

Sourced from loader-utils's changelog.

2.0.4 (2022-11-11)

Bug Fixes

2.0.3 (2022-10-20)

Bug Fixes

  • security: prototype pollution exploit (#217) (a93cf6f)

2.0.2 (2021-11-04)

Bug Fixes

  • base64 generation and unicode characters (#197) (8c2d24e)

2.0.1 (2021-10-29)

Bug Fixes

2.0.0 (2020-03-17)

⚠ BREAKING CHANGES

  • minimum required Node.js version is 8.9.0 (#166) (c937e8c)
  • the getOptions method returns empty object on empty query (#167) (b595cfb)
  • Use md4 by default

Commits


Updates react-scripts from 4.0.3 to 5.0.1

Commits


Updates react-styleguidist from 11.1.6 to 11.2.0

Release notes

Sourced from react-styleguidist's releases.

v11.2.0

11.2.0 (2022-01-27)

Features

v11.1.8

11.1.8 (2022-01-10)

Bug Fixes

  • Remove is-directory, use fs module directly (#1897) (77a2a2e)

v11.1.7

11.1.7 (2021-06-02)

Bug Fixes

Commits
  • 92518df feat: Webpack 5 support (#1903)
  • 6415cb6 Build(deps): Bump url-parse from 1.4.7 to 1.5.3 (#1896)
  • 6ca3c4c chore: Add npm 'cache' to 'release' workflow (#1899)
  • 7d62618 chore: Add npm 'cache' to 'danger' workflow (#1900)
  • 9114b4a docs: Fix code block formatting in Maintenance.md (#1908)
  • 54be33b chore: Add npm 'cache' to 'release' workflow (#1901)
  • 48e98b8 chore: Add npm 'cache' to Node.js workflow (#1898)
  • 77a2a2e fix: Remove is-directory, use fs module directly (#1897)
  • 0a477a6 docs: Add more funding options
  • 33b6796 Build(deps): Bump prismjs from 1.24.0 to 1.25.0 in /examples/webpack (#1892)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/bcgov/ag-pssg-sdlc/network/alerts).
github-actions[bot] commented 1 year ago

:lock: The security scan detected 2 potential secrets in the code.

path                                    line  secret
------------------------------------  ------  ------------------
.github/workflows/api-dotnetcore.yml     132  f5f11ab3c73f737...
.github/workflows/app-react.yml           78  83c8083f22204c5...