Closed dependabot[bot] closed 3 months ago
I've tested this locally and everything seems to be ok.
The windows tests are known to be broken on main
and we'll get those fixed soon. I'm a tiny bit concerned about the CLI test failures, but I tried using source maps and the evaluation log viewing and they seemed fine.
It seems this upgrade has definitely broken test/vscode-tests/cli-integration/sourcemap.test.ts
which is testing jumping to CodeQL code from an evaluator log. I'll ask the CodeQL team if anyone can investigate this.
Let's see if this works. @aeisenberg I've pushed your changes over to aeisenberg/tmp
so they're not lost.
The problem was that the gulp.src(_).pipe(gulp.dest(_))
pattern for copying a file in gulp doesn't work with binary files in gulp v5 since gulp v5 encodes things you open with src
as UTF-8 by default. This broke the WebAssembly binary needed for the source-map
package. We can fix by using gulp.src(_, { encoding: false }).pipe(gulp.dest(_))
to copy the WebAssembly file.
Nice catch! That makes a lot of sense. Alternatively, we can avoid using gulp pipe
to copy that file and shell out to an executable for that. Whatever works more easily.
It feels vaguely nice to keep it part of the build system primitives, but I don't feel strongly about it.
Bumps braces to 3.0.3 and updates ancestor dependency gulp. These dependencies need to be updated together.
Updates
braces
from 3.0.2 to 3.0.3Commits
74b2db2
3.0.388f1429
update eslint. lint, fix unit tests.415d660
Snyk js braces 6838727 (#40)190510f
fix tests, skip 1 test in test/braces.expand716eb9f
readme bumpa5851e5
Merge pull request #37 from coderaiser/fix/vulnerability2092bd1
feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cf
fix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9
remove funding file665ab5d
update keepEscaping doc (#27)Updates
gulp
from 4.0.2 to 5.0.0Release notes
Sourced from gulp's releases.
... (truncated)
Changelog
Sourced from gulp's changelog.
... (truncated)
Commits
5c4c547
chore: Release 5.0.0 (#2762)bf72116
chore: Add index.mjs to files listb00de68
feat: Provide an ESM export (#2760)72668c6
chore!: Normalize repository, dropping node <10.13 support (#2758)85896d4
chore(docs): Update stream handbook link (#2711)818bd73
Docs: Remove gulp-sourcemaps because it is built-in (#2592)598f971
Docs: Fix broken link in recipe (#2571)9877de0
Docs: Guide CustomRegistries to maintain properties on tasks (fixes #2561) (#...f91c388
Docs: Remove typo in custom registry docs (#2543)df25250
Docs: Fix typo in task docs (#2524)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show