skevy / graphiql-app

Light, Electron-based Wrapper around GraphiQL
MIT License
2.95k stars 336 forks source link

Bump xmldom, plist and electron-packager #205

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Removes xmldom. It's no longer used after updating ancestor dependencies xmldom, plist and electron-packager. These dependencies need to be updated together.

Removes xmldom

Updates plist from 3.0.1 to 3.0.6

Changelog

Sourced from plist's changelog.

3.0.5 / 2022-03-23

  • [96e2303d05] Prototype Pollution using .parse() #114 (mario-canva)
  • update browserify from 16 to 17

3.0.4 / 2021-08-27

  • inline xmldom@0.6.0 to eliminate security warning false positive (Mike Reinstein)

3.0.3 / 2021-08-04

  • update xmldom to 0.6.0 to patch critical vulnerability (Mike Reinstein)
  • remove flaky saucelabs teseting badge (Mike Reinstein)

3.0.2 / 2021-03-25

  • update xmldom to 0.5.0 to patch critical vulnerability (Mike Reinstein)
  • update saucelab credentials to point at mreinstein's saucelabs account (Mike Reinstein)
  • remove a bunch of test versions from the matrix because they weren't working in zuul + sauce (Mike Reinstein)
Commits


Updates electron-packager from 12.2.0 to 16.0.0

Release notes

Sourced from electron-packager's releases.

16.0.0

Fixed

  • Properly import info logger (#1405)

Added

  • Node 16 & 18 support (#1399)

Changed

  • Bump got to 2.0.0 (#1397)

Removed

  • Node 12 support (#1399)

15.5.2

Fixed

  • Package should not log info on --quiet flag
  • Ignore node_gyp_bins directory if it exists

15.5.0

Added

  • New universal architecture supported when packaging for macOS to generate a universal app
  • osxUniveral option to allow providing options to @electron/universal when packaging a universal app

15.4.0

Added

  • extendHelperInfo option to allow extending helper app Info.plist files (#1233)
  • Automatically insert ElectronAsarIntegrity into Info.plist files (#1279)

Fixed

  • Compatibility with electron-notarize@^1.1.0 (#1278)

15.3.0

Added

  • Bundled app validation to ensure that both package.json and the main entry point exist (#1257)
  • Support for customizing Windows targets on darwin/arm64 (#1260)
  • Support for customizing Windows targets on WSL without Wine installed (#1260)

15.2.0

Added

... (truncated)

Changelog

Sourced from electron-packager's changelog.

16.0.0 - 2022-08-23

Fixed

  • Properly import info logger (#1405)

Changed

  • Bump got to 2.0.0 (#1397)

Removed

  • Node 12 support (#1399)

15.5.2 - 2022-08-22

Fixed

  • Package should not log info on --quiet flag
  • Ignore node_gyp_bins directory if it exists

15.5.1 - 2022-04-20

Fixed

  • Univeral builds single-arch components are now built sequentially instead of in parallel to fix race conditions in hooks
  • The typescript definition for HookFunction now correctly allows an error to be passed

15.5.0 - 2022-04-19

Added

  • New universal architecture supported when packaging for macOS to generate a universal app
  • osxUniveral option to allow providing options to @electron/universal when packaging a universal app

15.4.0 - 2021-09-10

Added

  • extendHelperInfo option to allow extending helper app Info.plist files (#1233)

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by vertedinde, a new releaser for electron-packager since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/skevy/graphiql-app/network/alerts).