chore (deps): bump the patch-updates group with 6 updates#2323
chore (deps): bump the patch-updates group with 6 updates#2323GCHQDeveloper581 merged 2 commits intomasterfrom
Conversation
Bumps the patch-updates group with 6 updates: | Package | From | To | | --- | --- | --- | | [jimp](https://github.com/jimp-dev/jimp) | `1.6.0` | `1.6.1` | | [jsrsasign](https://github.com/kjur/jsrsasign) | `11.1.1` | `11.1.2` | | [protobufjs](https://github.com/protobufjs/protobuf.js) | `7.5.4` | `7.5.5` | | [grunt](https://github.com/gruntjs/grunt) | `1.6.1` | `1.6.2` | | [postcss](https://github.com/postcss/postcss) | `8.5.8` | `8.5.10` | | [webpack](https://github.com/webpack/webpack) | `5.106.0` | `5.106.2` | Updates `jimp` from 1.6.0 to 1.6.1 - [Release notes](https://github.com/jimp-dev/jimp/releases) - [Changelog](https://github.com/jimp-dev/jimp/blob/v1.6.1/CHANGELOG.md) - [Commits](jimp-dev/jimp@v1.6.0...v1.6.1) Updates `jsrsasign` from 11.1.1 to 11.1.2 - [Release notes](https://github.com/kjur/jsrsasign/releases) - [Changelog](https://github.com/kjur/jsrsasign/blob/master/ChangeLog.txt) - [Commits](kjur/jsrsasign@11.1.1...11.1.2) Updates `protobufjs` from 7.5.4 to 7.5.5 - [Release notes](https://github.com/protobufjs/protobuf.js/releases) - [Changelog](https://github.com/protobufjs/protobuf.js/blob/master/CHANGELOG.md) - [Commits](protobufjs/protobuf.js@protobufjs-v7.5.4...protobufjs-v7.5.5) Updates `grunt` from 1.6.1 to 1.6.2 - [Release notes](https://github.com/gruntjs/grunt/releases) - [Changelog](https://github.com/gruntjs/grunt/blob/main/CHANGELOG) - [Commits](gruntjs/grunt@v1.6.1...v1.6.2) Updates `postcss` from 8.5.8 to 8.5.10 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.8...8.5.10) Updates `webpack` from 5.106.0 to 5.106.2 - [Release notes](https://github.com/webpack/webpack/releases) - [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md) - [Commits](webpack/webpack@v5.106.0...v5.106.2) --- updated-dependencies: - dependency-name: jimp dependency-version: 1.6.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patch-updates - dependency-name: jsrsasign dependency-version: 11.1.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patch-updates - dependency-name: protobufjs dependency-version: 7.5.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: patch-updates - dependency-name: grunt dependency-version: 1.6.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch-updates - dependency-name: postcss dependency-version: 8.5.10 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch-updates - dependency-name: webpack dependency-version: 5.106.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: patch-updates ... Signed-off-by: dependabot[bot] <support@github.com>
313c34a to
b490111
Compare
|
Noting that the updated jsrsasign announces upcoming EOL for that project - #2325 raised in response. |
GCHQDeveloper581
left a comment
There was a problem hiding this comment.
I'm bumping this one.
protobufjs-7.5.5 is not listed in the changelog for the project (or in the github releases), and is only 2 days old.
On the balance of probabilities it is fine:
- there is a corresponding tag in the repo
- a quick scan of the diff between the package tgzs doesn't immediately throw up anything obviously scary
However it doesn't appear to be a vulnerability fix so, with an abundance of caution, I think we'll wait another week and see what the verdict of time is.
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
|
There's now a critical vulnerability in protobufjs 7.5.4 so logic for closing no longer applies. |
GCHQDeveloper581
left a comment
There was a problem hiding this comment.
Due diligence:
- checked for any reported supply chain issues with new versions
- protobufjs 7.5.5 does not appear in the project ChangeLog. However there is a critical vulnerability in the previous version, and 7.5.5 is specifically mentioned in the project originated announcement of that vulnerability
- basic inspection of diffs for these updates
- all tests pass
Bumps the patch-updates group with 6 updates:
1.6.01.6.111.1.111.1.27.5.47.5.51.6.11.6.28.5.88.5.105.106.05.106.2Updates
jimpfrom 1.6.0 to 1.6.1Release notes
Sourced from jimp's releases.
Changelog
Sourced from jimp's changelog.
... (truncated)
Commits
7e6a956Bump version to: v1.6.1 [skip ci]cf9ed93Update contributors [skip ci]7851672Update CHANGELOG.md [skip ci]e1bfa93Update file-type from ^16 to ^21.3.3 in@jimp/core(#1400)b6b0e41fix docs importsc943994docs: correct GitHub repo link (#1340)f3e6b9eDoc updates (closes #1342)Updates
jsrsasignfrom 11.1.1 to 11.1.2Release notes
Sourced from jsrsasign's releases.
Changelog
Sourced from jsrsasign's changelog.
... (truncated)
Commits
d568de311.1.2 release08f659ddelete sponsorship66ff9batext updated3370bftext updateUpdates
protobufjsfrom 7.5.4 to 7.5.5Changelog
Sourced from protobufjs's changelog.
Commits
b7bdfafchore: release 7.5.5ff7b2affix: filter invalid characters from the type name (#2127)086b19dfix: do not allow setting proto in Message constructor (#2126)Maintainer changes
This version was pushed to npm by fenster, a new releaser for protobufjs since your current version.
Updates
gruntfrom 1.6.1 to 1.6.2Changelog
Sourced from grunt's changelog.
Commits
f49016e1.6.2662e097Update minimatch to 3.1.5 to fix CVEsa29fd18CI: add Node.js 24 to version matrixf757c4fUpdate linksb5aa834Merge pull request #1792 from UlisesGascon/security-md8d2dea2docs: refresh security policyaa15bdcMerge pull request #1786 from stscoundrel/ci-node-22ee5b2a3Merge pull request #1787 from gruntjs/add-commercial-supportc0e2b42Readme updates re: supportc4f037dCI: update GH actions V3 -> V4Maintainer changes
This version was pushed to npm by krinkle, a new releaser for grunt since your current version.
Updates
postcssfrom 8.5.8 to 8.5.10Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
33b9790Release 8.5.10 version536c79eEscape </style> in CSS output (#2074)afa96b2Update dependencies (#2073)effe88bTypo (#2072)3ee79a2Thread model (#2071)2e0683dCreate incident response docs (#2070)fe88ac2Release 8.5.9 versionc551632Avoid RegExp when we can use simple JS89a6b74Move SECURITY.txt for docs folder to keep GitHub page cleaner6ceb8a4Create SECURITY.mdUpdates
webpackfrom 5.106.0 to 5.106.2Release notes
Sourced from webpack's releases.
Changelog
Sourced from webpack's changelog.
Commits
0d7e3e0chore(release): new release (#20815)d5df118chore(deps): bump actions/cache in the dependencies group (#20839)5f0874bfix: make asset modules available in JS when referenced from CSS and lazy JS ...b63ab37chore(deps): bump test/test262-cases in the dependencies group (#20792)313dfc5ci: improve time for windows (#20840)a553f61test: update test262 (#20841)1ef747cfix: CSS@importshould inherit parent's exportType over parser config (#20838)485d4cechore(deps): updateopen-cli(#20834)46042b9chore(deps): no outdated strip-ansi (#20835)8c7700bfix: handle@charsetat-rules in CSS modulesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions