citp / news-disinformation-study

A research project on how web users consume, are exposed to, and share news online.
8 stars 2 forks source link

Bump shell-quote and web-ext #109

Open dependabot[bot] opened 2 years ago

dependabot[bot] commented 2 years ago

Bumps shell-quote and web-ext. These dependencies needed to be updated together. Updates shell-quote from 1.6.1 to 1.7.3

Release notes

Sourced from shell-quote's releases.

v1.7.2

  • Fix a regression introduced in 1.6.3. This reverts the Windows path quoting fix. (144e1c2)

v1.7.1

  • Fix $ being removed when not part of an environment variable name. (@​Adman in #32)

v1.7.0

  • Add support for parsing >> and >& redirection operators. (@​forivall in #16)
  • Add support for parsing <( process substitution operator. (@​cuonglm in #15)

v1.6.3

  • Fix Windows path quoting problems. (@​dy in #34)

v1.6.2

  • Remove dependencies in favour of native methods. (@​zertosh in #21)
Changelog

Sourced from shell-quote's changelog.

1.7.3

  • Fix a security issue where the regex for windows drive letters allowed some shell meta-characters to escape the quoting rules. (CVE-2021-42740)

1.7.2

  • Fix a regression introduced in 1.6.3. This reverts the Windows path quoting fix. (144e1c2)

1.7.1

  • Fix $ being removed when not part of an environment variable name. (@​Adman in #32)

1.7.0

  • Add support for parsing >> and >& redirection operators. (@​forivall in #16)
  • Add support for parsing <( process substitution operator. (@​cuonglm in #15)

1.6.3

  • Fix Windows path quoting problems. (@​dy in #34)

1.6.2

  • Remove dependencies in favour of native methods. (@​zertosh in #21)
Commits


Updates web-ext from 6.1.0 to 6.8.0

Release notes

Sourced from web-ext's releases.

6.8.0

Features

  • web-ext lint: Updated to use addons-linter v4.14.0 (#2386)
    • Imported Firefox 98.0b10 API schema
    • Updated browser-compat-data
    • Fixed TypeError raised in opendialog-remote-uri rule
    • See all addons-linter changes: 4.9.0...4.14.0

Bug Fixes

  • web-ext run:
    • Improved debounce to prevent multiple extension reloads on consecutive file changes (#2385) (6c53a01)
  • Replaced deprecated dependency event-to-promise with promise-toolbox/fromEvent (#2367) (2cfd843)

See all changes 6.7.0...6.8.0

6.7.0

Features

  • web-ext lint: Updated to use addons-linter v4.9.0 (#2374, #2376)
    • Imported Firefox 96.0b7 and 97.0b8 API schema
    • Updated known libraries hashes (added new DOMPurify versions)
    • Updated browser-compat-data
    • Improved memory usage and performance on linting big js files
    • See all addons-linter changes: 4.4.0...4.9.0

Bug Fixes

  • web-ext lint: Fixed unexpected linting failures triggered by conflicting eslint versions when web-ext is included as a dev dependency (#2245, fixed in #2374)
  • web-ext run -t chromium: Applied fix to reload extensions already enabled (#2365)
  • web-ext sign: Updated dependency sign-addon to v3.11.0 (#2377)

See all changes 6.6.0...6.7.0

6.6.0

Features

  • web-ext lint: updated to use addons-linter v4.4.0 (#2346, #2350)
    • Imported Firefox 94.0b8 and Firefox 95.0b8 API schema
    • Updated browser-compat-data
    • Updated to use eslint v8, which enables ECMAScript 2022 syntax (e.g. public field declaration and top-level await)
    • See all addons-linter changes: 3.20.0...4.4.0

Bug Fixes

  • web-ext run:
    • fixed issues related to the nodejs 17 dns resolution behavior on systems where localhost is resolved to an ipv6 address (#2337)
    • fixed issue with removing temporary profile on nodejs <= 14.4 (#2344, saadtazi/firefox-profile-js#128)

... (truncated)

Commits
  • c368750 chore: Bump package version for release 6.8.0
  • 1b2ee61 fix(deps): update dependency addons-linter to v4.14.0 (#2386)
  • 6c53a01 fix: Improved debounce to prevent multiple extension reloads on consecutive f...
  • 81083df chore: Updated .nsprc exceptions
  • 7899dce chore: Updated minimist version to 1.2.6 in package-lock.json
  • fc4da01 chore(ci): Migrate circleci jobs to cimg/node docker images
  • 2cfd843 fix: Replaced event-to-promise with promise-toolbox/fromEvent (#2367)
  • 238bf6d chore: Bump package version for release 6.7.0
  • 542995d fix(deps): update dependency sign-addon to v3.11.0 (#2377)
  • 32961b1 fix(deps): update dependency addons-linter to v4.9.0 (#2376)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/citp/news-disinformation-study/network/alerts).