stone-payments / emerald-web-framework

A open-source framework that makes it easy to build top quality components for high-performance financial applications
Apache License 2.0
82 stars 11 forks source link

chore(deps): bump got, @semantic-release/npm and semantic-release #444

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Removes got. It's no longer used after updating ancestor dependencies got, @semantic-release/npm and semantic-release. These dependencies need to be updated together.

Removes got

Updates @semantic-release/npm from 5.3.5 to 10.0.3

Release notes

Sourced from @​semantic-release/npm's releases.

v10.0.3

10.0.3 (2023-04-07)

Bug Fixes

  • deps: update dependency read-pkg to v8 (#602) (aaddc5c)

v10.0.2

10.0.2 (2023-03-22)

Bug Fixes

  • deps: update dependency fs-extra to v11.1.1 (#591) (31e0e27)

v10.0.1

10.0.1 (2023-03-22)

Bug Fixes

v10.0.0

10.0.0 (2023-03-22)

Bug Fixes

  • aggregate-error: upgraded to the latest version (7285e05)
  • deps: upgraded npm to v9 (2a79f80)
  • execa: upgraded to the latest version (7c74660)
  • normalize-url: upgraded to the latest version (b55bb01)
  • remove support for legacy auth (51ab3c8)
  • tempy: upgraded to the latest version of tempy (f1992a5)

Code Refactoring

  • esm: converted the package to esm (2d8ff15)

Features

  • node-versions: dropped support for node versions below v18 (aff3574)
  • semantic-release-peer: raised the minimum peer requirement to the first version that supports loading esm plugins (22e70ad)

BREAKING CHANGES

... (truncated)

Commits
  • aaddc5c fix(deps): update dependency read-pkg to v8 (#602)
  • 9cc40d8 chore(deps): lock file maintenance (#600)
  • 9a290d8 chore(deps): update dependency semantic-release to v21.0.1 (#599)
  • 355108b chore(deps): update dependency sinon to v15.0.3 (#597)
  • 6f90cc6 chore(deps): update dependency semantic-release to v21 (#596)
  • e4db268 chore(deps): pin dependency prettier to 2.8.7 (#595)
  • 4cadccf chore(deps): update dependency prettier to v2.8.7 (#594)
  • 617daa9 chore(deps): update dependency got to v12.6.0 (#440)
  • 7317dda chore(deps): update dependency c8 to v7.13.0 (#593)
  • 6acfed7 chore(deps): update dependency ava to v5.2.0 (#564)
  • Additional commits viewable in compare view


Updates semantic-release from 15.9.16 to 21.0.2

Release notes

Sourced from semantic-release's releases.

v21.0.2

21.0.2 (2023-04-28)

Bug Fixes

  • deps: update dependency @​semantic-release/release-notes-generator to v11 (#2778) (ac40804)

v21.0.1

21.0.1 (2023-04-01)

Bug Fixes

v21.0.0

21.0.0 (2023-03-24)

BREAKING CHANGES

  • deps: the npm plugin has updated the npm dependency to v9
  • legacy authentication using NPM_USERNAME and NPM_PASSWORD is no longer supported. Use NPM_TOKEN instead.

Bug Fixes

  • deps: bump @semantic-release/npm to ^10.0.0 (d647433)

v21.0.0-beta.6

21.0.0-beta.6 (2023-03-22)

Bug Fixes

  • deps: update dependency cosmiconfig to v8.1.2 (fbede54)
  • deps: update dependency execa to v7 (#2709) (31d9bfe)
  • deps: update dependency execa to v7.1.1 (c38b53a)

v21.0.0-beta.5

21.0.0-beta.5 (2023-03-22)

Bug Fixes

  • deps: updated to the latest version of the npm plugin (d647433)

v21.0.0-beta.4

... (truncated)

Commits
  • ac40804 fix(deps): update dependency @​semantic-release/release-notes-generator to v11...
  • e046ece ci(signatures): moved the audit step to the non-matrix stage
  • ef998ac ci(dependencies): audited signatures and provenance attestations of installed...
  • 278d8e6 docs(gh-actions): captured details about publishing with provenance from an a...
  • ddf4065 chore(deps): update dependency sinon to v15.0.4 (#2769)
  • 4bddb37 fix(deps): update dependency env-ci to v9 (#2757)
  • aa90774 chore(deps): update dependency testdouble to v3.17.2 (#2751)
  • d7e14f6 docs(artifactory): removed details about using artifactory with legacy auth
  • 4a943a5 chore(deps): pin dependencies (#2744)
  • f47a510 chore(deps): lock file maintenance (#2737)
  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/stone-payments/emerald-web-framework/network/alerts).
andremacdowell commented 1 year ago

@dependabot rebase

devsec-app-stone[bot] commented 1 year ago

:robot: Gandalf - Continuos AppSec

Gandalf badge

Este repositório está sendo monitorando de forma automática e contínua em busca de achados que possam comprometer à segurança da aplicação.

Para maiores detalhes, acesse aqui à plataforma.

O que é? | Dúvidas e/ou sugestões