ghoneycutt / puppet-module-pam

Puppet module to manage PAM
Other
18 stars 80 forks source link

Update json_pure requirement from ~> 2.1.0 to ~> 2.2.0 #207

Closed dependabot-preview[bot] closed 5 years ago

dependabot-preview[bot] commented 5 years ago

Updates the requirements on json_pure to permit the latest version.

Changelog *Sourced from [json_pure's changelog](https://github.com/flori/json/blob/master/CHANGES.md).* > ## 2019-02-21 (2.2.0) > * Adds support for 2.6 BigDecimal and ruby standard library Set datetype. > > ## 2017-04-18 (2.1.0) > * Allow passing of `decimal_class` option to specify a class as which to parse > JSON float numbers. > ## 2017-03-23 (2.0.4) > * Raise exception for incomplete unicode surrogates/character escape > sequences. This problem was reported by Daniel Gollahon (dgollahon). > * Fix arbitrary heap exposure problem. This problem was reported by Ahmad > Sherif (ahmadsherif). > > ## 2017-01-12 (2.0.3) > * Set `required_ruby_version` to 1.9 > * Some small fixes > > ## 2016-07-26 (2.0.2) > * Specify `required_ruby_version` for json\_pure. > * Fix issue [#295](https://github-redirect.dependabot.com/flori/json/issues/295) failure when parsing frozen strings. > > ## 2016-07-01 (2.0.1) > * Fix problem when requiring json\_pure and Parser constant was defined top > level. > * Add `RB_GC_GUARD` to avoid possible GC problem via Pete Johns. > * Store `current_nesting` on stack by Aaron Patterson. > > ## 2015-09-11 (2.0.0) > * Now complies to newest JSON RFC 7159. > * Implements compatibiliy to ruby 2.4 integer unification. > * Drops support for old rubies whose life has ended, that is rubies < 2.0. > Also see https://www.ruby-lang.org/en/news/2014/07/01/eol-for-1-8-7-and-1-9-2/ > * There were still some mentions of dual GPL licensing in the source, but JSON > has just the Ruby license that itself includes an explicit dual-licensing > clause that allows covered software to be distributed under the terms of > the Simplified BSD License instead for all ruby versions >= 1.9.3. This is > however a GPL compatible license according to the Free Software Foundation. > I changed these mentions to be consistent with the Ruby license setting in > the gemspec files which were already correct now. > > ## 2015-06-01 (1.8.3) > * Fix potential memory leak, thx to nobu. > > ## 2015-01-08 (1.8.2) > * Some performance improvements by Vipul A M . > * Fix by Jason R. Clark to avoid mutation of > `JSON.dump_default_options`. > * More tests by Michael Mac-Vicar and fixing > `space_before` accessor in generator. > * Performance on Jruby improved by Ben Browning . > * Some fixes to be compatible with the new Ruby 2.2 by Zachary Scott > ... (truncated)
Commits - [`6550c42`](https://github.com/flori/json/commit/6550c427e1e9b1e5e4f1c85346f7e319c647a876) Merge branch 'master' of github.com:flori/json - [`f53a0e3`](https://github.com/flori/json/commit/f53a0e36dc165f769ea8c03549d293fa3cc2a377) It's more trouble than it's worth. - [`3631dad`](https://github.com/flori/json/commit/3631dad29db6f6e940dc781b2867485bdff37648) Use which to resolve to actual path - [`81fbce0`](https://github.com/flori/json/commit/81fbce0aa66738b3ea9758db2aee44b80bb8f9a5) [fix] 2.5 compat on JRuby 9.2 Fixnum/Bignum -> Integer - [`aff3d4b`](https://github.com/flori/json/commit/aff3d4b1fd7c13dac94dc936089a2c332747f593) Always use underscore for match string - [`0e97fd4`](https://github.com/flori/json/commit/0e97fd419328dd8add71c451222fa219a8f8fa1e) Upgrade version to 1.6 - [`a0f3d12`](https://github.com/flori/json/commit/a0f3d125a4339b166bbe2432894517803732aca5) Bump version to 2.2.0 - [`3eb7e9e`](https://github.com/flori/json/commit/3eb7e9ed605d7aa035a124cc7d5ad71c734dd81f) Add some missing ruby 2.6 changes - [`bb80864`](https://github.com/flori/json/commit/bb80864914a79b1a9dc2d897e56d1d135324b638) Fix a typo. - [`ef2092f`](https://github.com/flori/json/commit/ef2092f4d288ff666bcf10ffa43e58a91c649293) Fix for bigdecimal updates - Additional commits viewable in [compare view](https://github.com/flori/json/compare/v2.1.0...v2.2.0)


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Automerge options (never/patch/minor, and dev/runtime dependencies) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired) Finally, you can contact us by mentioning @dependabot.