sigstore / sigstore-js

Code-signing for npm packages
Apache License 2.0
151 stars 20 forks source link

Bump the prod-deps group across 1 directory with 3 updates #1149

Closed dependabot[bot] closed 1 month ago

dependabot[bot] commented 1 month ago

Bumps the prod-deps group with 3 updates in the / directory: make-fetch-happen, @tufjs/repo-mock and tuf-js.

Updates make-fetch-happen from 13.0.0 to 13.0.1

Release notes

Sourced from make-fetch-happen's releases.

v13.0.1

13.0.1 (2024-04-30)

Bug Fixes

Chores

Changelog

Sourced from make-fetch-happen's changelog.

13.0.1 (2024-04-30)

Bug Fixes

Chores

Commits
  • 0b3ba78 chore: release 13.0.1 (#286)
  • 66018e3 fix: log errors on retry
  • 9e1329c chore: fix linting in tests
  • 4756bda chore: postinstall for dependabot template-oss PR
  • 91df666 chore: bump @​npmcli/template-oss from 4.21.3 to 4.21.4
  • ed73ef5 fix: always catch and emit cache write errors in promise (#288)
  • f5135ba chore: postinstall for dependabot template-oss PR
  • d31e8c9 chore: bump @​npmcli/template-oss from 4.21.1 to 4.21.3
  • 389ae35 chore: postinstall for dependabot template-oss PR
  • 10596a3 chore: bump @​npmcli/template-oss from 4.19.0 to 4.21.1
  • Additional commits viewable in compare view


Updates @tufjs/repo-mock from 2.0.0 to 2.0.1

Release notes

Sourced from @​tufjs/repo-mock's releases.

@​tufjs/repo-mock@​2.0.1

Patch Changes

  • 86d7dfa: Bump nock from 13.5.3 to 13.5.4
  • ec53d69: Bump nock from 13.5.1 to 13.5.3
  • 5369508: Bump nock from 13.4.0 to 13.5.0
  • 0d3c8ec: Bump nock from 13.5.0 to 13.5.1
  • Updated dependencies [a108f83]
    • @​tufjs/models@​2.0.1
Commits
  • a038052 Version Packages (#617)
  • 38d9e45 Bump oclif from 4.10.1 to 4.10.4 in the dev-deps group (#701)
  • 6a37b8d Bump the dev-deps group with 2 updates (#700)
  • e70004a Bump the prod-deps group with 2 updates (#698)
  • cb97343 change dependabot frequency to weekly (#699)
  • bf9c445 Bump the dev-deps group with 3 updates (#697)
  • 7574c73 Bump the dev-deps group across 1 directory with 3 updates (#696)
  • 7243187 Bump the minor-patch group across 1 directory with 3 updates (#695)
  • 66121c3 Bump the minor-patch group across 1 directory with 2 updates (#692)
  • be96e4b Bump the dev-deps group with 3 updates (#691)
  • Additional commits viewable in compare view


Updates tuf-js from 2.2.0 to 2.2.1

Release notes

Sourced from tuf-js's releases.

tuf-js@2.2.1

Patch Changes

  • e70004a: Bump make-fetch-happen from 13.0.0 to 13.0.1
  • Updated dependencies [a108f83]
    • @​tufjs/models@​2.0.1
Commits
  • a038052 Version Packages (#617)
  • 38d9e45 Bump oclif from 4.10.1 to 4.10.4 in the dev-deps group (#701)
  • 6a37b8d Bump the dev-deps group with 2 updates (#700)
  • e70004a Bump the prod-deps group with 2 updates (#698)
  • cb97343 change dependabot frequency to weekly (#699)
  • bf9c445 Bump the dev-deps group with 3 updates (#697)
  • 7574c73 Bump the dev-deps group across 1 directory with 3 updates (#696)
  • 7243187 Bump the minor-patch group across 1 directory with 3 updates (#695)
  • 66121c3 Bump the minor-patch group across 1 directory with 2 updates (#692)
  • be96e4b Bump the dev-deps group with 3 updates (#691)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
changeset-bot[bot] commented 1 month ago

🦋 Changeset detected

Latest commit: 462b1cf33fc4c102ab9e11eb4e74d6995a894993

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages | Name | Type | | -------------- | ----- | | @sigstore/sign | Patch | | @sigstore/oci | Patch | | @sigstore/tuf | Patch |

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR