cinecove / defunctr

Browser detection based on feature inspection
BSD 3-Clause "New" or "Revised" License
27 stars 2 forks source link

An in-range update of bower is breaking the build 🚨 #160

Closed greenkeeper[bot] closed 4 years ago

greenkeeper[bot] commented 6 years ago

☝️ Greenkeeper’s updated Terms of Service will come into effect on April 6th, 2018.

Version 1.8.3 of bower was just published.

Branch Build failing 🚨
Dependency bower
Current Version 1.8.2
Type devDependency

This version is covered by your current version range and after updating it in your project the build failed.

bower is a devDependency of this project. It might not break your production code or affect downstream projects, but probably breaks your build or test tools, which may prevent deploying or publishing.

Status Details - ✅ **continuous-integration/travis-ci/push** The Travis CI build passed [Details](https://travis-ci.org/cinecove/defunctr/builds/359494352?utm_source=github_status&utm_medium=notification) - ❌ **bitHound - Dependencies** 4 failing dependencies. [Details](https://www.bithound.io/github/cinecove/defunctr/dbc76766e70e4c1a4af4542d1d7152343ccd45b9/dependencies/npm#filter-failing-dep) - ✅ **bitHound - Code** No failing files. [Details](https://www.bithound.io/github/cinecove/defunctr/dbc76766e70e4c1a4af4542d1d7152343ccd45b9/files?status=passing)

FAQ and help There is a collection of [frequently asked questions](https://greenkeeper.io/faq.html). If those don’t help, you can always [ask the humans behind Greenkeeper](https://github.com/greenkeeperio/greenkeeper/issues/new).

Your Greenkeeper Bot :palm_tree:

greenkeeper[bot] commented 6 years ago

After pinning to 1.8.2 your tests are still failing. The reported issue might not affect your project. These imprecisions are caused by inconsistent test results.

greenkeeper[bot] commented 6 years ago

Version 1.8.4 just got published.

Your tests are still failing with this version. Compare the changes 🚨

Release Notes v1.8.4
  • Fixes release 1.8.3 by publishing with npm@3 instead of npm@5 (to include lib/node_modules)
greenkeeper[bot] commented 5 years ago

Your tests are passing again with this update. Explicitly upgrade to this version 🚀

Release Notes for v1.8.6

Fix Zip Slip Vulnerability of decompress-zip package: https://snyk.io/research/zip-slip-vulnerability

Note: v1.8.5 has been unpublished because of missing files

greenkeeper[bot] commented 5 years ago

Your tests are passing again with this update. Explicitly upgrade to this version 🚀

Release Notes for v1.8.7

Fixes side effect of fix from v1.8.6 that caused improper permissions for extracted folders

#2532

greenkeeper[bot] commented 5 years ago

Your tests are passing again with this update. Explicitly upgrade to this version 🚀

Release Notes for v1.8.8

Fix vulnerability related to extracting .tar.gz files that has similar effect to Zip Slip

Vulnerability is similar to Zip Slip allows for overriding and creating arbitrary files on filesystem

Needlessly to say, please upgrade this this version of Bower