New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Security] Update dependencies to the latest stable #6241
Conversation
Bumps [phantomjs-prebuilt](https://github.com/Medium/phantomjs) from 2.1.14 to 2.1.16. - [Release notes](https://github.com/Medium/phantomjs/releases) - [Commits](https://github.com/Medium/phantomjs/commits) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [husky](https://github.com/typicode/husky) from 0.14.3 to 1.2.1. - [Release notes](https://github.com/typicode/husky/releases) - [Changelog](https://github.com/typicode/husky/blob/master/CHANGELOG.md) - [Commits](typicode/husky@v0.14.3...v1.2.1) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [grunt-contrib-clean](https://github.com/gruntjs/grunt-contrib-clean) from 1.1.0 to 2.0.0. - [Release notes](https://github.com/gruntjs/grunt-contrib-clean/releases) - [Changelog](https://github.com/gruntjs/grunt-contrib-clean/blob/master/CHANGELOG) - [Commits](gruntjs/grunt-contrib-clean@v1.1.0...v2.0.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
…ntrib-clean-2.0.0 Bump grunt-contrib-clean from 1.1.0 to 2.0.0
Bump husky from 0.14.3 to 1.2.1
…s-prebuilt-2.1.16 Bump phantomjs-prebuilt from 2.1.14 to 2.1.16
Bumps [grunt-contrib-jasmine](https://github.com/gruntjs/grunt-contrib-jasmine) from 1.1.0 to 2.0.3. - [Release notes](https://github.com/gruntjs/grunt-contrib-jasmine/releases) - [Changelog](https://github.com/gruntjs/grunt-contrib-jasmine/blob/master/CHANGELOG) - [Commits](https://github.com/gruntjs/grunt-contrib-jasmine/commits/v2.0.3) Signed-off-by: dependabot[bot] <support@dependabot.com>
…ntrib-jasmine-2.0.3 Bump grunt-contrib-jasmine from 1.1.0 to 2.0.3
Bumps [node-sass](https://github.com/sass/node-sass) from 4.7.2 to 4.11.0. - [Release notes](https://github.com/sass/node-sass/releases) - [Changelog](https://github.com/sass/node-sass/blob/master/CHANGELOG.md) - [Commits](sass/node-sass@v4.7.2...v4.11.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
…s-4.11.0 Bump node-sass from 4.7.2 to 4.11.0
Bumps [tough-cookie](https://github.com/salesforce/tough-cookie) from 2.3.2 to 2.3.4. **This update includes security fixes.** - [Release notes](https://github.com/salesforce/tough-cookie/releases) - [Commits](salesforce/tough-cookie@v2.3.2...v2.3.4) Signed-off-by: dependabot[bot] <support@dependabot.com>
…okie-2.3.4 [Security] Bump tough-cookie from 2.3.2 to 2.3.4
Bumps [stringstream](https://github.com/mhart/StringStream) from 0.0.5 to 0.0.6. **This update includes security fixes.** - [Release notes](https://github.com/mhart/StringStream/releases) - [Commits](mhart/StringStream@v0.0.5...v0.0.6) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [sshpk](https://github.com/joyent/node-sshpk) from 1.13.0 to 1.16.0. **This update includes security fixes.** - [Release notes](https://github.com/joyent/node-sshpk/releases) - [Commits](TritonDataCenter/node-sshpk@v1.13.0...v1.16.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
…16.0 [Security] Bump sshpk from 1.13.0 to 1.16.0
Bumps [is-my-json-valid](https://github.com/mafintosh/is-my-json-valid) from 2.16.0 to 2.19.0. **This update includes security fixes.** - [Release notes](https://github.com/mafintosh/is-my-json-valid/releases) - [Commits](mafintosh/is-my-json-valid@v2.16.0...v2.19.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
…ream-0.0.6 [Security] Bump stringstream from 0.0.5 to 0.0.6
…on-valid-2.19.0 [Security] Bump is-my-json-valid from 2.16.0 to 2.19.0
Bumps [grunt-contrib-watch](https://github.com/gruntjs/grunt-contrib-watch) from 1.0.0 to 1.1.0. - [Release notes](https://github.com/gruntjs/grunt-contrib-watch/releases) - [Changelog](https://github.com/gruntjs/grunt-contrib-watch/blob/master/CHANGELOG) - [Commits](gruntjs/grunt-contrib-watch@v1.0.0...v1.1.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
…ontrib-watch-1.1.0 Bump grunt-contrib-watch from 1.0.0 to 1.1.0
Bumps [jasmine](https://github.com/jasmine/jasmine-npm) from 2.6.0 to 3.3.1. - [Release notes](https://github.com/jasmine/jasmine-npm/releases) - [Commits](jasmine/jasmine-npm@v2.6.0...v3.3.1) Signed-off-by: dependabot[bot] <support@dependabot.com>
…-3.3.1 Bump jasmine from 2.6.0 to 3.3.1
Bumps [grunt-contrib-uglify](https://github.com/gruntjs/grunt-contrib-uglify) from 3.0.1 to 4.0.0. - [Release notes](https://github.com/gruntjs/grunt-contrib-uglify/releases) - [Changelog](https://github.com/gruntjs/grunt-contrib-uglify/blob/master/CHANGELOG) - [Commits](gruntjs/grunt-contrib-uglify@v3.0.1...v4.0.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
…ontrib-uglify-4.0.0 Bump grunt-contrib-uglify from 3.0.1 to 4.0.0
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 7.0.4 to 8.1.0. - [Release notes](https://github.com/okonet/lint-staged/releases) - [Commits](lint-staged/lint-staged@v7.0.4...v8.1.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [grunt](https://github.com/gruntjs/grunt) from 1.0.1 to 1.0.3. - [Release notes](https://github.com/gruntjs/grunt/releases) - [Changelog](https://github.com/gruntjs/grunt/blob/master/CHANGELOG) - [Commits](gruntjs/grunt@v1.0.1...v1.0.3) Signed-off-by: dependabot[bot] <support@dependabot.com>
….0.3 Bump grunt from 1.0.1 to 1.0.3
…aged-8.1.0 Bump lint-staged from 7.0.4 to 8.1.0
Bumps [concat-stream](https://github.com/maxogden/concat-stream) from 1.5.0 to 1.6.2. **This update includes security fixes.** - [Release notes](https://github.com/maxogden/concat-stream/releases) - [Commits](max-mapper/concat-stream@v1.5.0...v1.6.2) Signed-off-by: dependabot[bot] <support@dependabot.com>
…taged-10.2.2 Bump lint-staged from 10.1.7 to 10.2.2
Bumps [node-sass](https://github.com/sass/node-sass) from 4.14.0 to 4.14.1. - [Release notes](https://github.com/sass/node-sass/releases) - [Changelog](https://github.com/sass/node-sass/blob/master/CHANGELOG.md) - [Commits](sass/node-sass@v4.14.0...v4.14.1) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…ass-4.14.1 Bump node-sass from 4.14.0 to 4.14.1
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 9.7.6 to 9.8.0. - [Release notes](https://github.com/postcss/autoprefixer/releases) - [Changelog](https://github.com/postcss/autoprefixer/blob/master/CHANGELOG.md) - [Commits](postcss/autoprefixer@9.7.6...9.8.0) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…efixer-9.8.0 Bump autoprefixer from 9.7.6 to 9.8.0
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.2 to 10.2.6. - [Release notes](https://github.com/okonet/lint-staged/releases) - [Commits](lint-staged/lint-staged@v10.2.2...v10.2.6) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…taged-10.2.6 Bump lint-staged from 10.2.2 to 10.2.6
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.6 to 10.2.7. - [Release notes](https://github.com/okonet/lint-staged/releases) - [Commits](lint-staged/lint-staged@v10.2.6...v10.2.7) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [websocket-extensions](https://github.com/faye/websocket-extensions-node) from 0.1.3 to 0.1.4. **This update includes a security fix.** - [Release notes](https://github.com/faye/websocket-extensions-node/releases) - [Changelog](https://github.com/faye/websocket-extensions-node/blob/master/CHANGELOG.md) - [Commits](faye/websocket-extensions-node@0.1.3...0.1.4) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…ket-extensions-0.1.4 [Security] Bump websocket-extensions from 0.1.3 to 0.1.4
…taged-10.2.7 Bump lint-staged from 10.2.6 to 10.2.7
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.7 to 10.2.9. - [Release notes](https://github.com/okonet/lint-staged/releases) - [Commits](lint-staged/lint-staged@v10.2.7...v10.2.9) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…taged-10.2.9 Bump lint-staged from 10.2.7 to 10.2.9
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.9 to 10.2.10. - [Release notes](https://github.com/okonet/lint-staged/releases) - [Commits](lint-staged/lint-staged@v10.2.9...v10.2.10) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…taged-10.2.10 Bump lint-staged from 10.2.9 to 10.2.10
Bumps [npm-registry-fetch](https://github.com/npm/registry-fetch) from 4.0.4 to 4.0.5. **This update includes a security fix.** - [Release notes](https://github.com/npm/registry-fetch/releases) - [Changelog](https://github.com/npm/npm-registry-fetch/blob/latest/CHANGELOG.md) - [Commits](https://github.com/npm/registry-fetch/commits) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…gistry-fetch-4.0.5 [Security] Bump npm-registry-fetch from 4.0.4 to 4.0.5
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 10.2.10 to 10.2.11. - [Release notes](https://github.com/okonet/lint-staged/releases) - [Commits](lint-staged/lint-staged@v10.2.10...v10.2.11) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…taged-10.2.11 Bump lint-staged from 10.2.10 to 10.2.11
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 9.8.0 to 9.8.4. - [Release notes](https://github.com/postcss/autoprefixer/releases) - [Changelog](https://github.com/postcss/autoprefixer/blob/master/CHANGELOG.md) - [Commits](postcss/autoprefixer@9.8.0...9.8.4) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…efixer-9.8.4 Bump autoprefixer from 9.8.0 to 9.8.4
Bumps [grunt](https://github.com/gruntjs/grunt) from 1.1.0 to 1.2.1. - [Release notes](https://github.com/gruntjs/grunt/releases) - [Changelog](https://github.com/gruntjs/grunt/blob/master/CHANGELOG) - [Commits](gruntjs/grunt@v1.1.0...v1.2.1) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…1.2.1 Bump grunt from 1.1.0 to 1.2.1
Can we please get this merged, this fixes a lot of security issues !!! |
My last comment is still valid, devDependencies are not security relevant and you bump things without checking if anything breaks. Please take a look at the breaking CI build. If we do these updates we will update dependabot on the fork. And using the same branch is discouraged as this will break when there are new commits on the v1-dev branch. |
I do not know how to fix the ci stuff and security issues are security issues no matter what they are used for and should be resolved to protect against these issues
…________________________________
From: Daniel Ruf <notifications@github.com>
Sent: Wednesday, July 8, 2020 7:33:53 AM
To: Dogfalo/materialize <materialize@noreply.github.com>
Cc: J.Townsend <townsend891@hotmail.com>; Author <author@noreply.github.com>
Subject: Re: [Dogfalo/materialize] [Security] Update dependencies to the latest stable (#6241)
Can we please get this merged, this fixes a lot of security issues !!!
My last comment is still valid, devDependencies are not security relevant and you bump things without checking if anything breaks. Please take a look at the breaking CI build. If we do these updates we will update dependabot on the fork.
And using the same branch is discouraged as this will break when there are new commits on the v1-dev branch.
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub<#6241 (comment)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/AA3V2QURECJZULGBKHTSY3LR2QHNDANCNFSM4GMKGSIQ>.
|
devDependencies are only for building materialize.js and never land in the materialize.js file or on any production server. We will apply needed updates (if relevant) one by one on the fork but not like this (all at once and breaking stuff). |
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 9.8.4 to 9.8.5. - [Release notes](https://github.com/postcss/autoprefixer/releases) - [Changelog](https://github.com/postcss/autoprefixer/blob/master/CHANGELOG.md) - [Commits](postcss/autoprefixer@9.8.4...9.8.5) Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
…efixer-9.8.5 Bump autoprefixer from 9.8.4 to 9.8.5
This updates all dependencies to the latest stable to fix multiple security issues and there is a new maintainer release for 2 dependencies as well, I recommend that the project sets up dependabot for the project to keep on top of the dependencies