Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Update dependencies to the latest stable #6241

Closed
wants to merge 236 commits into from
Closed

[Security] Update dependencies to the latest stable #6241

wants to merge 236 commits into from

Conversation

L1ghtn1ng
Copy link

@L1ghtn1ng L1ghtn1ng commented Dec 27, 2018

This updates all dependencies to the latest stable to fix multiple security issues and there is a new maintainer release for 2 dependencies as well, I recommend that the project sets up dependabot for the project to keep on top of the dependencies

dependabot-support and others added 28 commits December 27, 2018 08:28
Bumps [phantomjs-prebuilt](https://github.com/Medium/phantomjs) from 2.1.14 to 2.1.16.
- [Release notes](https://github.com/Medium/phantomjs/releases)
- [Commits](https://github.com/Medium/phantomjs/commits)

Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [husky](https://github.com/typicode/husky) from 0.14.3 to 1.2.1.
- [Release notes](https://github.com/typicode/husky/releases)
- [Changelog](https://github.com/typicode/husky/blob/master/CHANGELOG.md)
- [Commits](typicode/husky@v0.14.3...v1.2.1)

Signed-off-by: dependabot[bot] <support@dependabot.com>
…ntrib-clean-2.0.0

Bump grunt-contrib-clean from 1.1.0 to 2.0.0
…s-prebuilt-2.1.16

Bump phantomjs-prebuilt from 2.1.14 to 2.1.16
…ntrib-jasmine-2.0.3

Bump grunt-contrib-jasmine from 1.1.0 to 2.0.3
Bumps [node-sass](https://github.com/sass/node-sass) from 4.7.2 to 4.11.0.
- [Release notes](https://github.com/sass/node-sass/releases)
- [Changelog](https://github.com/sass/node-sass/blob/master/CHANGELOG.md)
- [Commits](sass/node-sass@v4.7.2...v4.11.0)

Signed-off-by: dependabot[bot] <support@dependabot.com>
…s-4.11.0

Bump node-sass from 4.7.2 to 4.11.0
Bumps [tough-cookie](https://github.com/salesforce/tough-cookie) from 2.3.2 to 2.3.4. **This update includes security fixes.**
- [Release notes](https://github.com/salesforce/tough-cookie/releases)
- [Commits](salesforce/tough-cookie@v2.3.2...v2.3.4)

Signed-off-by: dependabot[bot] <support@dependabot.com>
…okie-2.3.4

[Security] Bump tough-cookie from 2.3.2 to 2.3.4
Bumps [stringstream](https://github.com/mhart/StringStream) from 0.0.5 to 0.0.6. **This update includes security fixes.**
- [Release notes](https://github.com/mhart/StringStream/releases)
- [Commits](mhart/StringStream@v0.0.5...v0.0.6)

Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [sshpk](https://github.com/joyent/node-sshpk) from 1.13.0 to 1.16.0. **This update includes security fixes.**
- [Release notes](https://github.com/joyent/node-sshpk/releases)
- [Commits](TritonDataCenter/node-sshpk@v1.13.0...v1.16.0)

Signed-off-by: dependabot[bot] <support@dependabot.com>
…16.0

[Security] Bump sshpk from 1.13.0 to 1.16.0
Bumps [is-my-json-valid](https://github.com/mafintosh/is-my-json-valid) from 2.16.0 to 2.19.0. **This update includes security fixes.**
- [Release notes](https://github.com/mafintosh/is-my-json-valid/releases)
- [Commits](mafintosh/is-my-json-valid@v2.16.0...v2.19.0)

Signed-off-by: dependabot[bot] <support@dependabot.com>
…ream-0.0.6

[Security] Bump stringstream from 0.0.5 to 0.0.6
…on-valid-2.19.0

[Security] Bump is-my-json-valid from 2.16.0 to 2.19.0
…ontrib-watch-1.1.0

Bump grunt-contrib-watch from 1.0.0 to 1.1.0
Bumps [jasmine](https://github.com/jasmine/jasmine-npm) from 2.6.0 to 3.3.1.
- [Release notes](https://github.com/jasmine/jasmine-npm/releases)
- [Commits](jasmine/jasmine-npm@v2.6.0...v3.3.1)

Signed-off-by: dependabot[bot] <support@dependabot.com>
…ontrib-uglify-4.0.0

Bump grunt-contrib-uglify from 3.0.1 to 4.0.0
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 7.0.4 to 8.1.0.
- [Release notes](https://github.com/okonet/lint-staged/releases)
- [Commits](lint-staged/lint-staged@v7.0.4...v8.1.0)

Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [grunt](https://github.com/gruntjs/grunt) from 1.0.1 to 1.0.3.
- [Release notes](https://github.com/gruntjs/grunt/releases)
- [Changelog](https://github.com/gruntjs/grunt/blob/master/CHANGELOG)
- [Commits](gruntjs/grunt@v1.0.1...v1.0.3)

Signed-off-by: dependabot[bot] <support@dependabot.com>
…aged-8.1.0

Bump lint-staged from 7.0.4 to 8.1.0
@L1ghtn1ng L1ghtn1ng changed the title Update dependencies to the latest stable [Security] Update dependencies to the latest stable Dec 27, 2018
Bumps [concat-stream](https://github.com/maxogden/concat-stream) from 1.5.0 to 1.6.2. **This update includes security fixes.**
- [Release notes](https://github.com/maxogden/concat-stream/releases)
- [Commits](max-mapper/concat-stream@v1.5.0...v1.6.2)

Signed-off-by: dependabot[bot] <support@dependabot.com>
L1ghtn1ng and others added 23 commits May 9, 2020 17:11
…taged-10.2.2

Bump lint-staged from 10.1.7 to 10.2.2
Bumps [node-sass](https://github.com/sass/node-sass) from 4.14.0 to 4.14.1.
- [Release notes](https://github.com/sass/node-sass/releases)
- [Changelog](https://github.com/sass/node-sass/blob/master/CHANGELOG.md)
- [Commits](sass/node-sass@v4.14.0...v4.14.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…ass-4.14.1

Bump node-sass from 4.14.0 to 4.14.1
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 9.7.6 to 9.8.0.
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/master/CHANGELOG.md)
- [Commits](postcss/autoprefixer@9.7.6...9.8.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…efixer-9.8.0

Bump autoprefixer from 9.7.6 to 9.8.0
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.2 to 10.2.6.
- [Release notes](https://github.com/okonet/lint-staged/releases)
- [Commits](lint-staged/lint-staged@v10.2.2...v10.2.6)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…taged-10.2.6

Bump lint-staged from 10.2.2 to 10.2.6
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.6 to 10.2.7.
- [Release notes](https://github.com/okonet/lint-staged/releases)
- [Commits](lint-staged/lint-staged@v10.2.6...v10.2.7)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [websocket-extensions](https://github.com/faye/websocket-extensions-node) from 0.1.3 to 0.1.4. **This update includes a security fix.**
- [Release notes](https://github.com/faye/websocket-extensions-node/releases)
- [Changelog](https://github.com/faye/websocket-extensions-node/blob/master/CHANGELOG.md)
- [Commits](faye/websocket-extensions-node@0.1.3...0.1.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…ket-extensions-0.1.4

[Security] Bump websocket-extensions from 0.1.3 to 0.1.4
…taged-10.2.7

Bump lint-staged from 10.2.6 to 10.2.7
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.7 to 10.2.9.
- [Release notes](https://github.com/okonet/lint-staged/releases)
- [Commits](lint-staged/lint-staged@v10.2.7...v10.2.9)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…taged-10.2.9

Bump lint-staged from 10.2.7 to 10.2.9
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.9 to 10.2.10.
- [Release notes](https://github.com/okonet/lint-staged/releases)
- [Commits](lint-staged/lint-staged@v10.2.9...v10.2.10)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…taged-10.2.10

Bump lint-staged from 10.2.9 to 10.2.10
Bumps [npm-registry-fetch](https://github.com/npm/registry-fetch) from 4.0.4 to 4.0.5. **This update includes a security fix.**
- [Release notes](https://github.com/npm/registry-fetch/releases)
- [Changelog](https://github.com/npm/npm-registry-fetch/blob/latest/CHANGELOG.md)
- [Commits](https://github.com/npm/registry-fetch/commits)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…gistry-fetch-4.0.5

[Security] Bump npm-registry-fetch from 4.0.4 to 4.0.5
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.10 to 10.2.11.
- [Release notes](https://github.com/okonet/lint-staged/releases)
- [Commits](lint-staged/lint-staged@v10.2.10...v10.2.11)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…taged-10.2.11

Bump lint-staged from 10.2.10 to 10.2.11
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 9.8.0 to 9.8.4.
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/master/CHANGELOG.md)
- [Commits](postcss/autoprefixer@9.8.0...9.8.4)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…efixer-9.8.4

Bump autoprefixer from 9.8.0 to 9.8.4
Bumps [grunt](https://github.com/gruntjs/grunt) from 1.1.0 to 1.2.1.
- [Release notes](https://github.com/gruntjs/grunt/releases)
- [Changelog](https://github.com/gruntjs/grunt/blob/master/CHANGELOG)
- [Commits](gruntjs/grunt@v1.1.0...v1.2.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@L1ghtn1ng
Copy link
Author

Can we please get this merged, this fixes a lot of security issues !!!

@DanielRuf
Copy link
Contributor

Can we please get this merged, this fixes a lot of security issues !!!

My last comment is still valid, devDependencies are not security relevant and you bump things without checking if anything breaks. Please take a look at the breaking CI build. If we do these updates we will update dependabot on the fork.

And using the same branch is discouraged as this will break when there are new commits on the v1-dev branch.

@L1ghtn1ng
Copy link
Author

L1ghtn1ng commented Jul 8, 2020 via email

@DanielRuf
Copy link
Contributor

devDependencies are only for building materialize.js and never land in the materialize.js file or on any production server.

We will apply needed updates (if relevant) one by one on the fork but not like this (all at once and breaking stuff).

dependabot-preview bot and others added 2 commits July 13, 2020 06:20
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 9.8.4 to 9.8.5.
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/master/CHANGELOG.md)
- [Commits](postcss/autoprefixer@9.8.4...9.8.5)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…efixer-9.8.5

Bump autoprefixer from 9.8.4 to 9.8.5
@L1ghtn1ng L1ghtn1ng closed this Mar 1, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants