Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): Update dependency minimist to version 1.2.2 🌟 #6726

Merged
merged 1 commit into from
Mar 16, 2020

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 13, 2020

This PR contains the following updates:

Package Type Update Change
minimist dependencies patch 1.2.0 -> 1.2.2
minimist devDependencies patch 1.2.0 -> 1.2.2

GitHub Vulnerability Alerts

CVE-2020-7598

There are high severity security vulnerabilities in two of ESLints dependencies:
- acorn
- minimist

The releases 1.8.3 and lower of svjsl (JSLib-npm) are vulnerable, but only if installed in a developer environment. A patch has been released (v1.8.4) which fixes these vulnerabilities.

Identifiers:


Release Notes

substack/minimist

v1.2.2

Compare Source

v1.2.1

Compare Source


Renovate configuration

📅 Schedule: "" in timezone America/New_York.

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot added renovate Triggered by renovatebot type: dependencies labels Mar 13, 2020
@cypress-bot
Copy link
Contributor

cypress-bot bot commented Mar 13, 2020

Below are some guidelines Cypress uses when reviewing dependency updates.

Dependency Update Instructions

  • Read through the entire changelog of the dependency's changes. If a changelog is not available, check every commit made to the dependency. NOTE - do not rely on semver to indicate breaking changes - every product does not follow this standard.
  • Add a PR review comment noting any relevant changes in the dependency.
  • If any of the following requirements cannot be met, leave a comment in the review selecting 'Request changes', otherwise 'Approve'.

Dependency Updates Checklist

  • Code using the dependency has been updated to accommodate any breaking changes
  • The dependency still supports the version of Node that the package requires.
  • The PR been tagged with a release in ZenHub.
  • Appropriate labels have been added to the PR (for example: label type: breaking change if it is a breaking change)

@cypress
Copy link

cypress bot commented Mar 13, 2020



Test summary

6966 0 97 0


Run details

Project cypress
Status Passed
Commit c12fcba
Started Mar 13, 2020 9:13 PM
Ended Mar 13, 2020 9:20 PM
Duration 07:15 💡
OS Linux Debian - 10.1
Browser Multiple

View run in Cypress Dashboard ➡️


This comment has been generated by cypress-bot as a result of this project's GitHub integration settings. You can manage this integration in this project's settings in the Cypress Dashboard

Copy link
Member

@jennifer-shehane jennifer-shehane left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. No breaking changes - just bug fixes.

@jennifer-shehane jennifer-shehane merged commit aad4860 into develop Mar 16, 2020
@renovate renovate bot deleted the renovate/npm-minimist-vulnerability branch March 16, 2020 05:15
@cypress-bot
Copy link
Contributor

cypress-bot bot commented Mar 16, 2020

Released in 4.2.0.

This comment thread has been locked. If you are still experiencing this issue after upgrading to
Cypress v4.2.0, please open a new issue.

@cypress-bot cypress-bot bot locked as resolved and limited conversation to collaborators Mar 16, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
renovate Triggered by renovatebot type: dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants