Closed dependabot[bot] closed 2 months ago
I'll try to instruct it to recreate it because it's been downgrading some dependencies again (axios in this case)
@dependabot recreate
@hyperledger/cacti-maintainers It is still downgrading axios so I'll just close this.
@dependabot close
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.
To ignore these dependencies, configure ignore rules in dependabot.yml
Bumps the npm_and_yarn group with 7 updates in the / directory:
5.88.2
5.94.0
1.7.2
1.7.4
6.0.0
6.0.1
6.5.4
6.5.7
6.19.2
6.19.3
6.8.3
6.9.7
2.3.6
2.3.7
Bumps the npm_and_yarn group with 1 update in the /examples/cactus-example-discounted-asset-trade directory: elliptic. Bumps the npm_and_yarn group with 2 updates in the /packages/cactus-plugin-ledger-connector-fabric directory: bl and elliptic. Bumps the npm_and_yarn group with 1 update in the /packages/cactus-plugin-ledger-connector-iroha2 directory: undici. Bumps the npm_and_yarn group with 1 update in the /packages/cactus-plugin-ledger-connector-polkadot directory: bl. Bumps the npm_and_yarn group with 1 update in the /packages/cactus-test-tooling directory: elliptic. Bumps the npm_and_yarn group with 1 update in the /weaver/sdks/fabric/interoperation-node-sdk directory: elliptic.
Updates
webpack
from 5.88.2 to 5.94.0Release notes
Sourced from webpack's releases.
... (truncated)
Commits
eabf85d
chore(release): 5.94.0955e057
security: fix DOM clobbering in auto public path9822387
test: fixcbb86ed
test: fix5ac3d7f
fix: unexpected asi generation with sequence expression2411661
security: fix DOM clobbering in auto public pathb8c03d4
fix: unexpected asi generation with sequence expressionf46a03c
revert: do not use heuristic fallback for "module-import"60f1898
fix: do not use heuristic fallback for "module-import"66306aa
Revert "fix: module-import get fallback from externalsPresets"Updates
axios
from 1.7.2 to 1.7.4Release notes
Sourced from axios's releases.
Changelog
Sourced from axios's changelog.
Commits
abd24a7
chore(release): v1.7.4 (#6544)6b6b605
fix(sec): CVE-2024-39338 (#6539) (#6543)07a661a
fix(sec): disregard protocol-relative URL to remediate SSRF (#6539)c6cce43
chore(release): v1.7.3 (#6521)e3c76fc
fix(adapter): fix progress event emitting; (#6518)85d4d0e
fix(fetch): fix withCredentials request config (#6505)92cd8ed
chore(github): update ISSUE_TEMPLATE.md (#6519)8966ee7
fix(xhr): return original config on errors from XHR adapter (#6515)Updates
bl
from 6.0.0 to 6.0.1Release notes
Sourced from bl's releases.
Changelog
Sourced from bl's changelog.
... (truncated)
Commits
bea5abf
chore(release): 6.0.1 [skip ci]6965a1d
fix: release with Node.js 180885658
chore(deps-dev): bump typescript from 4.9.5 to 5.0.260bee1b
chore(no-release): bump actions/setup-node from 3.5.1 to 3.6.0 (#120)7d7e731
doc: fix BigInt method names8be6dd6
chore(no-release): bump typescript from 4.8.4 to 4.9.3 (#118)Updates
elliptic
from 6.5.4 to 6.5.7Commits
3e46a48
6.5.7accb61e
lib: DER signature decoding correction03e06e1
6.5.67ac5360
Merge commit from fork7570078
6.5.5206da2e
lib: lint0a78e03
[Fix] restore node < 4 compatUpdates
undici
from 6.19.2 to 6.19.3Release notes
Sourced from undici's releases.
Commits
99102cc
Bumped v6.19.3b696a78
In CITGM, skip tests that are flaky there (#3413)Updates
qs
from 6.8.3 to 6.9.7Changelog
Sourced from qs's changelog.
... (truncated)
Commits
4cd0032
v6.9.7e799ba5
[Fix]parse
: ignore__proto__
keys (#428)02ca358
[Robustness]stringify
: avoid relying on a globalundefined
(#427)4a17709
[Fix]stringify
: avoid encoding arrayformat comma when `encodeValuesOnly = ...c0e13e9
[readme] remove travis badge; add github actions/codecov badges; update URLs4113a5f
[Tests] clean up stringify tests slightly749a584
[Docs] add note and links for coercing primitive values (#408)cce2082
[meta] fix README.md (#399)c44f0c5
Revert "[meta] ignore eclint transitive audit warning"e6cfd8b
[actions] backport actions from mainUpdates
requirejs
from 2.3.6 to 2.3.7Commits
1874a29
Rev to 2.3.7152f450
Merge pull request #1016 from requirejs/jr/1854-pollutionecc356a
Fixes requirejs/requirejs#1854, pollutionacec536
SECURITY.mdUpdates
elliptic
from 6.5.4 to 6.5.7Commits
3e46a48
6.5.7accb61e
lib: DER signature decoding correction03e06e1
6.5.67ac5360
Merge commit from fork7570078
6.5.5206da2e
lib: lint0a78e03
[Fix] restore node < 4 compatUpdates
bl
from 6.0.12 to 6.0.14Release notes
Sourced from bl's releases.
Changelog
Sourced from bl's changelog.
... (truncated)
Commits
bea5abf
chore(release): 6.0.1 [skip ci]6965a1d
fix: release with Node.js 180885658
chore(deps-dev): bump typescript from 4.9.5 to 5.0.260bee1b
chore(no-release): bump actions/setup-node from 3.5.1 to 3.6.0 (#120)7d7e731
doc: fix BigInt method names8be6dd6
chore(no-release): bump typescript from 4.8.4 to 4.9.3 (#118)Updates
elliptic
from 6.5.4 to 6.5.7Commits
3e46a48
6.5.7accb61e
lib: DER signature decoding correction03e06e1
6.5.67ac5360
Merge commit from fork7570078
6.5.5206da2e
lib: lint0a78e03
[Fix] restore node < 4 compatUpdates
undici
from 6.19.2 to 6.19.8Release notes
Sourced from undici's releases.
Commits
99102cc
Bumped v6.19.3b696a78
In CITGM, skip tests that are flaky there (#3413)Updates
bl
from 6.0.0 to 6.0.14Release notes
Sourced from bl's releases.
Changelog
Sourced from bl's changelog.
... (truncated)
Commits
bea5abf
chore(release): 6.0.1 [skip ci]6965a1d
fix: release with Node.js 180885658
chore(deps-dev): bump typescript from 4.9.5 to 5.0.260bee1b
chore(no-release): bump actions/setup-node from 3.5.1 to 3.6.0 (#120)7d7e731
doc: fix BigInt method names8be6dd6
chore(no-release): bump typescript from 4.8.4 to 4.9.3 (#118)Updates
elliptic
from 6.5.4 to 6.5.7Commits
3e46a48
6.5.7accb61e
lib: DER signature decoding correction03e06e1
6.5.67ac5360
Merge commit from fork7570078
6.5.5206da2e
lib: lint0a78e03
[Fix] restore node < 4 compatUpdates
elliptic
from 6.5.4 to 6.5.7Commits
3e46a48
6.5.7accb61e
lib: DER signature decoding correction03e06e1
6.5.67ac5360
Merge commit from fork7570078
6.5.5206da2e
lib: lint0a78e03
[Fix] restore node < 4 compatDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show