Open dependabot[bot] opened 1 year ago
:warning: We detected 88 security issues in this pull request:
Mode: paranoid | Total findings: 88 | Considered vulnerability: 88
👉 Go to the dashboard for detailed results.
📥 Happy? Share your feedback with us.
Bumps minimist to 1.2.8 and updates ancestor dependency karma-mocha. These dependencies need to be updated together.
Updates
minimist
from 1.2.5 to 1.2.8Changelog
Sourced from minimist's changelog.
... (truncated)
Commits
6901ee2
v1.2.8a026794
Merge tag 'v0.2.3'c0b2661
v0.2.363b8fee
[Fix] Fix long option followed by single dash (#17)72239e6
[Tests] Remove duplicate test (#12)34b0f1c
[eslint] fix indentation3226afa
[Dev Deps] add missingnpmignore
dev dep098873c
[Dev Deps] update@ljharb/eslint-config
,aud
9ec4d27
[Fix] Fix long option followed by single dashba92fe6
[actions] Avoid 0.6 tests due to build failuresMaintainer changes
This version was pushed to npm by ljharb, a new releaser for minimist since your current version.
Updates
karma-mocha
from 1.3.0 to 2.0.1Release notes
Sourced from karma-mocha's releases.
Changelog
Sourced from karma-mocha's changelog.
Commits
bb5be9b
chore(release): 2.0.1 [skip ci]1a8226c
fix(deps): Report fails without emit 'test end' event (#223)5828416
chore(release): 2.0.0 [skip ci]4e35a55
chore(ci): semantic-release on success (#221)00b24b6
chore(deps-dev): bump eslint from 2.13.1 to 4.18.2 (#220)f7ec4e7
Merge pull request #218 from karma-runner/semanitic-release5a5b6d5
feat(ci): enable semanitic-release36404cf
Merge pull request #217 from franktopel/minimist-updatebab0416
updated minimum version of minimist dependency to ^1.2.3 instead of 1.2.03f9e4b7
Revert "updated minimum version of minimist dependency to ^1.2.3 instead of 1...Maintainer changes
This version was pushed to npm by karmarunnerbot, a new releaser for karma-mocha since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/turkdevops/web.dev/network/alerts).