Closed dependabot[bot] closed 4 years ago
@dependabot squash and merge
Coveralls notifications@github.com 於 2020年7月19日 週日 上午2:41 寫道:
[image: Coverage Status] https://coveralls.io/builds/32166211
Coverage remained the same at 100.0% when pulling 2450bac https://github.com/yyc1217/twzipcode-data/commit/2450bac6d581c367b4c32c904b66738c63a72816 on dependabot/npm_and_yarn/lodash-4.17.19 into 56de43d https://github.com/yyc1217/twzipcode-data/commit/56de43de658a57d07ecf341f0a429533f703f67c on master.
— You are receiving this because you have alerting access. Reply to this email directly, view it on GitHub https://github.com/yyc1217/twzipcode-data/pull/6#issuecomment-660523992, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAOM6KLE6EPYSRW6Q3XPVATR4HUG7ANCNFSM4PAHG6VQ .
Bumps lodash from 4.17.15 to 4.17.19.
Release notes
Sourced from lodash's releases.
Commits
d7fbc52
Bump to v4.17.192e1c0f2
Add npm-package1b6c282
Bump to v4.17.18a370ac8
Bump to v4.17.171144918
Rebuild lodash and docs3a3b0fd
Bump to v4.17.16c84fe82
fix(zipObjectDeep): prototype pollution (#4759)e7b28ea
Sanitize sourceURL so it cannot affect evaled code (#4518)0cec225
Fix lodash.isEqual for circular references (#4320) (#4515)94c3a81
Document matches* shorthands for over* methods (#4510) (#4514)Maintainer changes
This version was pushed to npm by mathias, a new releaser for lodash since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/yyc1217/twzipcode-data/network/alerts).