rsksmart / 2wp-app

MIT License
12 stars 15 forks source link

build(deps): bump @rsksmart/rlogin-ledger-provider from 1.0.3 to 1.0.4 #863

Closed dependabot[bot] closed 2 weeks ago

dependabot[bot] commented 3 weeks ago

Bumps @rsksmart/rlogin-ledger-provider from 1.0.3 to 1.0.4.

Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
github-actions[bot] commented 3 weeks ago

Dependency Review

The following issues were found:

See the Details below.

License Issues

package.json

PackageVersionLicenseIssue Type
@rsksmart/rlogin-ledger-provider^1.0.4NullUnknown License

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
npm/@chainsafe/as-sha256 0.4.2 UnknownUnknown
npm/@chainsafe/persistent-merkle-tree 0.6.1 :green_circle: 3.8
Details
CheckScoreReason
Maintained:warning: 0project is archived
Code-Review:green_circle: 9Found 13/14 approved changesets -- score normalized to 9
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Binary-Artifacts:green_circle: 10no binaries found in the repo
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Packaging:warning: -1packaging workflow not detected
Pinned-Dependencies:warning: 1dependency not pinned by hash detected -- score normalized to 1
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Security-Policy:warning: 0security policy file not detected
Fuzzing:warning: 0project is not fuzzed
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities:warning: 039 existing vulnerabilities detected
npm/@chainsafe/ssz 0.11.1 UnknownUnknown
npm/@ethereumjs/common 3.2.0 :green_circle: 5.5
Details
CheckScoreReason
Code-Review:green_circle: 10all changesets reviewed
Maintained:green_circle: 1030 commit(s) and 24 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
License:warning: 0license file not detected
Packaging:warning: -1packaging workflow not detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Security-Policy:warning: 0security policy file not detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing:warning: 0project is not fuzzed
Pinned-Dependencies:green_circle: 3dependency not pinned by hash detected -- score normalized to 3
Vulnerabilities:green_circle: 82 existing vulnerabilities detected
npm/@ethereumjs/tx 4.1.2 :green_circle: 5.5
Details
CheckScoreReason
Code-Review:green_circle: 10all changesets reviewed
Maintained:green_circle: 1030 commit(s) and 24 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
License:warning: 0license file not detected
Packaging:warning: -1packaging workflow not detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Security-Policy:warning: 0security policy file not detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Fuzzing:warning: 0project is not fuzzed
Pinned-Dependencies:green_circle: 3dependency not pinned by hash detected -- score normalized to 3
Vulnerabilities:green_circle: 82 existing vulnerabilities detected
npm/@ledgerhq/cryptoassets-evm-signatures 13.5.1 UnknownUnknown
npm/@ledgerhq/devices 8.4.4 UnknownUnknown
npm/@ledgerhq/domain-service 1.2.9 UnknownUnknown
npm/@ledgerhq/errors 6.19.1 UnknownUnknown
npm/@ledgerhq/evm-tools 1.2.4 UnknownUnknown
npm/@ledgerhq/hw-app-eth 6.40.2 UnknownUnknown
npm/@ledgerhq/hw-transport 6.31.4 UnknownUnknown
npm/@ledgerhq/hw-transport-mocker 6.29.4 UnknownUnknown
npm/@ledgerhq/hw-transport-webhid 6.29.4 UnknownUnknown
npm/@ledgerhq/hw-transport-webusb 6.29.4 UnknownUnknown
npm/@ledgerhq/live-env 2.4.0 UnknownUnknown
npm/@ledgerhq/types-live 6.52.3 UnknownUnknown
npm/@noble/curves 1.4.2 UnknownUnknown
npm/@rsksmart/rlogin-ledger-provider 1.0.4 UnknownUnknown
npm/@scure/bip32 1.4.0 UnknownUnknown
npm/@scure/bip39 1.3.0 UnknownUnknown
npm/assert 2.1.0 :green_circle: 4.2
Details
CheckScoreReason
Code-Review:warning: 1Found 4/22 approved changesets -- score normalized to 1
Maintained:warning: 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Security-Policy:green_circle: 10security policy file detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Branch-Protection:warning: 0branch protection not enabled on development/release branches
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
npm/axios 1.7.7 :green_circle: 5.8
Details
CheckScoreReason
Maintained:green_circle: 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Code-Review:green_circle: 5Found 11/21 approved changesets -- score normalized to 5
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases:warning: -1no releases found
Packaging:warning: -1packaging workflow not detected
Security-Policy:green_circle: 10security policy file detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies:green_circle: 3dependency not pinned by hash detected -- score normalized to 3
Fuzzing:warning: 0project is not fuzzed
SAST:green_circle: 9SAST tool detected but not run on all commits
Vulnerabilities:warning: 038 existing vulnerabilities detected
npm/browserify-zlib 0.2.0 UnknownUnknown
npm/ethereum-cryptography 2.2.1 :green_circle: 5.9
Details
CheckScoreReason
Code-Review:green_circle: 8Found 5/6 approved changesets -- score normalized to 8
Maintained:green_circle: 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Binary-Artifacts:green_circle: 10no binaries found in the repo
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Branch-Protection:green_circle: 3branch protection is not maximal on development and all release branches
Pinned-Dependencies:green_circle: 6dependency not pinned by hash detected -- score normalized to 6
Security-Policy:warning: 0security policy file not detected
Fuzzing:warning: 0project is not fuzzed
Packaging:green_circle: 10packaging workflow detected
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities:green_circle: 82 existing vulnerabilities detected
npm/keccak 3.0.4 :green_circle: 3.5
Details
CheckScoreReason
Code-Review:warning: 1Found 5/30 approved changesets -- score normalized to 1
Maintained:warning: 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Packaging:warning: -1packaging workflow not detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Branch-Protection:warning: 0branch protection not enabled on development/release branches
Security-Policy:warning: 0security policy file not detected
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
npm/pako 1.0.11 :green_circle: 5.7
Details
CheckScoreReason
Code-Review:warning: 1Found 3/30 approved changesets -- score normalized to 1
Maintained:warning: 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Packaging:warning: -1packaging workflow not detected
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Branch-Protection:warning: 0branch protection not enabled on development/release branches
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:green_circle: 10project is fuzzed
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Security-Policy:green_circle: 10security policy file detected
npm/qs 6.13.0 :green_circle: 6.8
Details
CheckScoreReason
Code-Review:warning: 1Found 4/29 approved changesets -- score normalized to 1
Maintained:green_circle: 1012 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10
License:green_circle: 10license file detected
CII-Best-Practices:green_circle: 5badge detected: Passing
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Token-Permissions:green_circle: 10GitHub workflow tokens follow principle of least privilege
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Security-Policy:green_circle: 9security policy file detected
npm/react 18.3.1 :green_circle: 5.2
Details
CheckScoreReason
Code-Review:green_circle: 7Found 21/28 approved changesets -- score normalized to 7
Maintained:green_circle: 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
License:green_circle: 10license file detected
CII-Best-Practices:warning: 2badge detected: InProgress
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases:warning: -1no releases found
Security-Policy:green_circle: 10security policy file detected
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts:green_circle: 9binaries present in source code
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing:warning: 0project is not fuzzed
Vulnerabilities:warning: 0193 existing vulnerabilities detected
npm/react-dom 18.3.1 :green_circle: 5.2
Details
CheckScoreReason
Code-Review:green_circle: 7Found 21/28 approved changesets -- score normalized to 7
Maintained:green_circle: 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
License:green_circle: 10license file detected
CII-Best-Practices:warning: 2badge detected: InProgress
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases:warning: -1no releases found
Security-Policy:green_circle: 10security policy file detected
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts:green_circle: 9binaries present in source code
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing:warning: 0project is not fuzzed
Vulnerabilities:warning: 0193 existing vulnerabilities detected
npm/scheduler 0.23.2 :green_circle: 5.2
Details
CheckScoreReason
Code-Review:green_circle: 7Found 21/28 approved changesets -- score normalized to 7
Maintained:green_circle: 1030 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
License:green_circle: 10license file detected
CII-Best-Practices:warning: 2badge detected: InProgress
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Signed-Releases:warning: -1no releases found
Security-Policy:green_circle: 10security policy file detected
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Binary-Artifacts:green_circle: 9binaries present in source code
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Fuzzing:warning: 0project is not fuzzed
Vulnerabilities:warning: 0193 existing vulnerabilities detected
npm/semver 7.6.3 :green_circle: 6.7
Details
CheckScoreReason
Code-Review:green_circle: 10all changesets reviewed
Maintained:green_circle: 55 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 5
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Security-Policy:green_circle: 10security policy file detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Packaging:warning: -1packaging workflow not detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Signed-Releases:warning: -1no releases found
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
SAST:green_circle: 9SAST tool detected but not run on all commits
npm/side-channel 1.0.6 :green_circle: 4.4
Details
CheckScoreReason
Code-Review:warning: 0Found 1/30 approved changesets -- score normalized to 0
Maintained:warning: 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Signed-Releases:warning: -1no releases found
Branch-Protection:warning: -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Fuzzing:warning: 0project is not fuzzed
Security-Policy:green_circle: 9security policy file detected
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
npm/url 0.11.4 :green_circle: 4.1
Details
CheckScoreReason
Code-Review:warning: 1Found 4/27 approved changesets -- score normalized to 1
Maintained:green_circle: 66 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 6
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Security-Policy:warning: 0security policy file not detected
Vulnerabilities:green_circle: 100 existing vulnerabilities detected
Branch-Protection:warning: 0branch protection not enabled on development/release branches
Fuzzing:warning: 0project is not fuzzed
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
npm/utility-types 3.11.0 :green_circle: 3.4
Details
CheckScoreReason
Code-Review:green_circle: 3Found 9/30 approved changesets -- score normalized to 3
Maintained:warning: 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
CII-Best-Practices:warning: 0no effort to earn an OpenSSF best practices badge detected
License:green_circle: 10license file detected
Signed-Releases:warning: -1no releases found
Packaging:warning: -1packaging workflow not detected
Dangerous-Workflow:green_circle: 10no dangerous workflow patterns detected
Security-Policy:green_circle: 10security policy file detected
Token-Permissions:warning: 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts:green_circle: 10no binaries found in the repo
Pinned-Dependencies:warning: 0dependency not pinned by hash detected -- score normalized to 0
Branch-Protection:warning: 0branch protection not enabled on development/release branches
Fuzzing:warning: 0project is not fuzzed
SAST:warning: 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities:warning: 045 existing vulnerabilities detected
npm/@rsksmart/rlogin-ledger-provider ^1.0.4 UnknownUnknown

Scanned Manifest Files

package-lock.json
  • axios@1.6.3
  • axios@0.26.1
  • @chainsafe/as-sha256@0.4.2
  • @chainsafe/persistent-merkle-tree@0.6.1
  • @chainsafe/ssz@0.11.1
  • @ethereumjs/common@3.2.0
  • @ethereumjs/tx@4.1.2
  • @ledgerhq/cryptoassets-evm-signatures@13.5.1
  • @ledgerhq/devices@8.4.4
  • @ledgerhq/domain-service@1.2.9
  • @ledgerhq/errors@6.19.1
  • @ledgerhq/evm-tools@1.2.4
  • @ledgerhq/hw-app-eth@6.40.2
  • @ledgerhq/hw-transport@6.31.4
  • @ledgerhq/hw-transport-mocker@6.29.4
  • @ledgerhq/hw-transport-webhid@6.29.4
  • @ledgerhq/hw-transport-webusb@6.29.4
  • @ledgerhq/live-env@2.4.0
  • @ledgerhq/types-live@6.52.3
  • @noble/curves@1.4.2
  • @rsksmart/rlogin-ledger-provider@1.0.4
  • @scure/bip32@1.4.0
  • @scure/bip39@1.3.0
  • assert@2.1.0
  • axios@1.7.7
  • browserify-zlib@0.2.0
  • ethereum-cryptography@2.2.1
  • keccak@3.0.4
  • pako@1.0.11
  • qs@6.13.0
  • react@18.3.1
  • react-dom@18.3.1
  • scheduler@0.23.2
  • semver@7.6.3
  • side-channel@1.0.6
  • url@0.11.4
  • utility-types@3.11.0
  • @ledgerhq/cryptoassets@9.11.1
  • @ledgerhq/cryptoassets@11.1.0
  • @ledgerhq/devices@8.0.7
  • @ledgerhq/devices@8.2.2
  • @ledgerhq/domain-service@1.1.8
  • @ledgerhq/errors@6.16.3
  • @ledgerhq/evm-tools@1.0.10
  • @ledgerhq/hw-app-eth@6.34.3
  • @ledgerhq/hw-transport@6.28.8
  • @ledgerhq/hw-transport@6.30.5
  • @ledgerhq/hw-transport-mocker@6.28.5
  • @ledgerhq/hw-transport-webhid@6.27.19
  • @ledgerhq/live-env@0.6.1
  • @ledgerhq/live-network@1.1.8
  • @ledgerhq/live-promise@0.0.2
  • @ledgerhq/types-live@6.38.1
  • @rsksmart/rlogin-ledger-provider@1.0.3
  • assert@2.0.0
  • es6-object-assign@1.1.0
  • lru-cache@7.18.3
  • qs@6.11.2
  • react@17.0.2
  • react-dom@17.0.2
  • scheduler@0.20.2
  • semver@7.6.0
  • side-channel@1.0.4
  • url@0.11.1
  • utility-types@3.10.0
package.json
  • @rsksmart/rlogin-ledger-provider@^1.0.4
  • @rsksmart/rlogin-ledger-provider@^1.0.3
dependabot[bot] commented 2 weeks ago

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.