chore(deps): bump the dependencies group across 1 directory with 4 updates #87
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the dependencies group with 4 updates in the / directory: @nodesecure/js-x-ray, @nodesecure/npm-registry-sdk, @nodesecure/scanner and pacote.
Updates
@nodesecure/js-x-ray
from 6.3.0 to 7.3.0Release notes
Sourced from
@nodesecure/js-x-ray
's releases.... (truncated)
Commits
5ad1570
7.3.0fbd7346
fix(isOneLineRequire): must return true for a one line require with no export...6b5e612
chore(deps-dev): bump glob in the development-dependencies group (#282)e7fad47
chore(deps): bump the github-actions group with 4 updates (#281)47759c2
docs: add fless-lab as a contributor for code (#277)0612155
chore: add deprecation warnings for legacyrunASTAnalysis
and `runASTAnalys...a3af86a
feat(AstAnalyser): add synchronous analyseFile function version (#275)a6b6c04
chore(deps-dev): bump c8 in the development-dependencies group (#274)51f5cd6
chore(deps): bump the github-actions group with 5 updates (#273)96318de
7.2.0Updates
@nodesecure/npm-registry-sdk
from 2.1.1 to 3.0.0Release notes
Sourced from
@nodesecure/npm-registry-sdk
's releases.Commits
8cbc336
3.0.03680828
Merge pull request #144 from NodeSecure/nodesecure-types37e390d
fix: skip metadata tests because NPM registry interface is broken0fc5410
refactor: use@nodesecure/npm-types
b29922a
fix(packument): add missing properties for NPM provenance (#135)29d3a56
chore(deps): bump the dependencies group with 1 update (#134)3a43637
chore(deps-dev): bump the development-dependencies group with 1 update (#133)fa917a6
chore(deps): bump the github-actions group with 4 updates (#132)c2d219d
chore: using dependabot groups (#127)Updates
@nodesecure/scanner
from 5.3.0 to 6.1.0Release notes
Sourced from
@nodesecure/scanner
's releases.... (truncated)
Commits
5d95dc3
chore(scanner): v6.1.0059e497
chore: update to@nodesecure/rc
v4 (#295)829a165
feat(npm-types): add new type PackTarball to describe npm package JSON output...c9d7a78
chore: update@nodesecure/vulnera
to v2.0.1 (#293)b9a33ec
chore(npm-types): v1.1.1eecb953
Merge pull request #292 from NodeSecure/fix-tree-walker-workspaces68eaf7f
fix(contact): avoid flaky match with common name3f6d0df
fix(npm-types): do not extends name & version for WorkspacesPackageJSON66b06fc
fix(tree-walker): implement default name & version for workspacesd0836a9
Scanner v6.0.2 (#291)Updates
pacote
from 17.0.7 to 18.0.6Release notes
Sourced from pacote's releases.
... (truncated)
Changelog
Sourced from pacote's changelog.
... (truncated)
Commits
f54ea83
chore: release 18.0.6 (#370)79441a5
fix: clean up requires (#371)b19aacb
fix: isolate full and corgi packuments in packumentCache (#369)8b58a32
chore: release 18.0.5 (#367)5e75582
fix: dont set _contentLength if not in headers (#368)1b6950b
fix(refactor): symbol cleanup (#365)005d8a9
chore: release 18.0.4 (#364)5fd2c80
fix(linting): no-unused-varsa235f37
chore: postinstall for dependabot template-oss PRd867639
chore: bump@npmcli/template-oss
to 4.22.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions