Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Bump lodash.template from 4.4.0 to 4.5.0 #1964

Merged
merged 1 commit into from
Jan 3, 2020

Conversation

dependabot-preview[bot]
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Dec 17, 2019

Bumps lodash.template from 4.4.0 to 4.5.0. This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

High severity vulnerability that affects lodash, lodash-es, lodash-amd, lodash.template, lodash.merge, lodash.mergewith, and lodash.defaultsdeep
Affected versions of lodash are vulnerable to Prototype Pollution.
The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Affected versions: < 4.5.0

Commits
  • ab73503 Bump to v4.5.0.
  • a4f7d4c Rebuild lodash and docs.
  • cca5ac6 Fix npm-test by removing the call to test-docs.
  • 6e2fb92 Remove unused baseArity.
  • 4f702e2 Specify utf8 encoding.
  • b188f90 Add fp tests for iteratee shorthands.
  • 7b93dc9 Ensure clone methods clone expando properties of boolean, number, & string ob...
  • 664d66a Make string tests more consistent.
  • d9dc0e6 Add _.invertBy tests.
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added dependencies security 🚨 Pull requests that address a security vulnerability labels Dec 17, 2019
@rust-highfive
Copy link

Thanks for the pull request, and welcome! The Rust team is excited to review your changes, and you should hear from @carols10cents (or someone else) soon.

If any changes to this PR are deemed necessary, please add them as extra commits. This ensures that the reviewer can see what has changed since they last reviewed the code. Due to the way GitHub handles out-of-date commits, this should also make it reasonably obvious what issues have or haven't been addressed. Large or tricky changes may require several passes of review and changes.

Please see the contribution instructions for more information.

@Turbo87
Copy link
Member

Turbo87 commented Dec 17, 2019

@bors r+

@bors
Copy link
Contributor

bors commented Dec 17, 2019

📌 Commit 87202ec has been approved by Turbo87

bors added a commit that referenced this pull request Dec 17, 2019
…te-4.5.0, r=Turbo87

[Security] Bump lodash.template from 4.4.0 to 4.5.0

Bumps [lodash.template](https://github.com/lodash/lodash) from 4.4.0 to 4.5.0. **This update includes a security fix.**
<details>
<summary>Vulnerabilities fixed</summary>

*Sourced from The GitHub Security Advisory Database.*

> **High severity vulnerability that affects lodash, lodash-es, lodash-amd, lodash.template, lodash.merge, lodash.mergewith, and lodash.defaultsdeep**
> Affected versions of lodash are vulnerable to Prototype Pollution.
> The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
>
> Affected versions: < 4.5.0

</details>
<details>
<summary>Commits</summary>

- [`ab73503`](lodash/lodash@ab73503) Bump to v4.5.0.
- [`a4f7d4c`](lodash/lodash@a4f7d4c) Rebuild lodash and docs.
- [`cca5ac6`](lodash/lodash@cca5ac6) Fix npm-test by removing the call to test-docs.
- [`9f7f9fc`](lodash/lodash@9f7f9fc) Adjust heading order. [ci skip]
- [`6e2fb92`](lodash/lodash@6e2fb92) Remove unused `baseArity`.
- [`4f702e2`](lodash/lodash@4f702e2) Specify utf8 encoding.
- [`b188f90`](lodash/lodash@b188f90) Add fp tests for iteratee shorthands.
- [`7b93dc9`](lodash/lodash@7b93dc9) Ensure clone methods clone expando properties of boolean, number, & string ob...
- [`664d66a`](lodash/lodash@664d66a) Make string tests more consistent.
- [`d9dc0e6`](lodash/lodash@d9dc0e6) Add `_.invertBy` tests.
- Additional commits viewable in [compare view](lodash/lodash@4.4.0...4.5.0)
</details>
<br />

[![Dependabot compatibility score](https://api.dependabot.com/badges/compatibility_score?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)](https://dependabot.com/compatibility-score.html?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)

</details>
@bors
Copy link
Contributor

bors commented Dec 17, 2019

⌛ Testing commit 87202ec with merge 0023761...

@bors
Copy link
Contributor

bors commented Dec 17, 2019

💥 Test timed out

@locks
Copy link
Contributor

locks commented Dec 18, 2019

@bors r+

@bors
Copy link
Contributor

bors commented Dec 18, 2019

💡 This pull request was already approved, no need to approve it again.

@bors
Copy link
Contributor

bors commented Dec 18, 2019

📌 Commit 87202ec has been approved by locks

bors added a commit that referenced this pull request Dec 18, 2019
…te-4.5.0, r=locks

[Security] Bump lodash.template from 4.4.0 to 4.5.0

Bumps [lodash.template](https://github.com/lodash/lodash) from 4.4.0 to 4.5.0. **This update includes a security fix.**
<details>
<summary>Vulnerabilities fixed</summary>

*Sourced from The GitHub Security Advisory Database.*

> **High severity vulnerability that affects lodash, lodash-es, lodash-amd, lodash.template, lodash.merge, lodash.mergewith, and lodash.defaultsdeep**
> Affected versions of lodash are vulnerable to Prototype Pollution.
> The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
>
> Affected versions: < 4.5.0

</details>
<details>
<summary>Commits</summary>

- [`ab73503`](lodash/lodash@ab73503) Bump to v4.5.0.
- [`a4f7d4c`](lodash/lodash@a4f7d4c) Rebuild lodash and docs.
- [`cca5ac6`](lodash/lodash@cca5ac6) Fix npm-test by removing the call to test-docs.
- [`9f7f9fc`](lodash/lodash@9f7f9fc) Adjust heading order. [ci skip]
- [`6e2fb92`](lodash/lodash@6e2fb92) Remove unused `baseArity`.
- [`4f702e2`](lodash/lodash@4f702e2) Specify utf8 encoding.
- [`b188f90`](lodash/lodash@b188f90) Add fp tests for iteratee shorthands.
- [`7b93dc9`](lodash/lodash@7b93dc9) Ensure clone methods clone expando properties of boolean, number, & string ob...
- [`664d66a`](lodash/lodash@664d66a) Make string tests more consistent.
- [`d9dc0e6`](lodash/lodash@d9dc0e6) Add `_.invertBy` tests.
- Additional commits viewable in [compare view](lodash/lodash@4.4.0...4.5.0)
</details>
<br />

[![Dependabot compatibility score](https://api.dependabot.com/badges/compatibility_score?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)](https://dependabot.com/compatibility-score.html?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)

</details>
@bors
Copy link
Contributor

bors commented Dec 18, 2019

⌛ Testing commit 87202ec with merge ccb617b...

@bors
Copy link
Contributor

bors commented Dec 18, 2019

💥 Test timed out

@carols10cents
Copy link
Member

@bors retry

@bors
Copy link
Contributor

bors commented Dec 18, 2019

⌛ Testing commit 87202ec with merge 22330d9...

bors added a commit that referenced this pull request Dec 18, 2019
…te-4.5.0, r=locks

[Security] Bump lodash.template from 4.4.0 to 4.5.0

Bumps [lodash.template](https://github.com/lodash/lodash) from 4.4.0 to 4.5.0. **This update includes a security fix.**
<details>
<summary>Vulnerabilities fixed</summary>

*Sourced from The GitHub Security Advisory Database.*

> **High severity vulnerability that affects lodash, lodash-es, lodash-amd, lodash.template, lodash.merge, lodash.mergewith, and lodash.defaultsdeep**
> Affected versions of lodash are vulnerable to Prototype Pollution.
> The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
>
> Affected versions: < 4.5.0

</details>
<details>
<summary>Commits</summary>

- [`ab73503`](lodash/lodash@ab73503) Bump to v4.5.0.
- [`a4f7d4c`](lodash/lodash@a4f7d4c) Rebuild lodash and docs.
- [`cca5ac6`](lodash/lodash@cca5ac6) Fix npm-test by removing the call to test-docs.
- [`9f7f9fc`](lodash/lodash@9f7f9fc) Adjust heading order. [ci skip]
- [`6e2fb92`](lodash/lodash@6e2fb92) Remove unused `baseArity`.
- [`4f702e2`](lodash/lodash@4f702e2) Specify utf8 encoding.
- [`b188f90`](lodash/lodash@b188f90) Add fp tests for iteratee shorthands.
- [`7b93dc9`](lodash/lodash@7b93dc9) Ensure clone methods clone expando properties of boolean, number, & string ob...
- [`664d66a`](lodash/lodash@664d66a) Make string tests more consistent.
- [`d9dc0e6`](lodash/lodash@d9dc0e6) Add `_.invertBy` tests.
- Additional commits viewable in [compare view](lodash/lodash@4.4.0...4.5.0)
</details>
<br />

[![Dependabot compatibility score](https://api.dependabot.com/badges/compatibility_score?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)](https://dependabot.com/compatibility-score.html?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)

</details>
@Turbo87
Copy link
Member

Turbo87 commented Dec 18, 2019

hmm, something must be wrong with this... but strangely the TravisCI build is fine and only the homu check times out 🤔

@carols10cents
Copy link
Member

@bors cancel

idk if this works

@Turbo87
Copy link
Member

Turbo87 commented Dec 18, 2019

@bors r-

@bors
Copy link
Contributor

bors commented Dec 18, 2019

💥 Test timed out

@dependabot-preview
Copy link
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@pietroalbini pietroalbini reopened this Dec 19, 2019
@pietroalbini
Copy link
Member

@bors r=Turbo87

@bors
Copy link
Contributor

bors commented Dec 19, 2019

@pietroalbini: 🔑 Insufficient privileges: Not in reviewers

@dependabot-preview dependabot-preview bot force-pushed the dependabot/npm_and_yarn/lodash.template-4.5.0 branch from 87202ec to 2770b07 Compare December 19, 2019 09:19
@bors
Copy link
Contributor

bors commented Dec 23, 2019

💥 Test timed out

@Turbo87
Copy link
Member

Turbo87 commented Dec 23, 2019

... and yet it still timed out 😩

@smarnach
Copy link
Contributor

It again did not build the right commit: https://travis-ci.com/rust-lang/crates.io/builds/142101885

@Turbo87
Copy link
Member

Turbo87 commented Dec 23, 2019

oh, you're totally right. I was confused by the green checkmark on 029403a, but apparently that was only for the GitHub Actions CI 🤦‍♂

@pietroalbini
Copy link
Member

If y'all feel confident about GitHub Actions we could switch bors to gate on it instead of Travis CI.

@Turbo87
Copy link
Member

Turbo87 commented Dec 23, 2019

the GH Actions have been a bit flaky for me in the past days. I'm not entirely confident about them.

they generally work quite well for me on other projects though, so maybe something about our setup still needs to be improved.

@carols10cents
Copy link
Member

the GH Actions have been a bit flaky for me in the past days. I'm not entirely confident about them

Do you happen to have a link to some of the GH Actions flakiness?

@jtgeibel
Copy link
Member

For some reason, backend tests on Actions occasionally error out with panicked at 'Could not run jobs: NoMessageReceived'. I may have seen this once or twice locally in the past, but for some reason GH Actions seems to hit this fairly frequently, when Travis does not.

Here's a link @carols10cents: https://github.com/rust-lang/crates.io/runs/361113429

@jtgeibel
Copy link
Member

@carols10cents here is also an example of the same failure on beta, so this isn't just a nightly thing. This PR didn't make any changes to the backend, and the other channels passed, but beta had the NoMessageReceived spurious failure. https://github.com/rust-lang/crates.io/runs/359774519

@smarnach
Copy link
Contributor

The GitHub Actions build also takes 2.5 times as long as the Travis build.

@smarnach
Copy link
Contributor

smarnach commented Jan 2, 2020

@bors retry

@bors
Copy link
Contributor

bors commented Jan 2, 2020

⌛ Testing commit 29d1f3f with merge d38c38b...

bors added a commit that referenced this pull request Jan 2, 2020
…te-4.5.0, r=smarnach

[Security] Bump lodash.template from 4.4.0 to 4.5.0

Bumps [lodash.template](https://github.com/lodash/lodash) from 4.4.0 to 4.5.0. **This update includes a security fix.**
<details>
<summary>Vulnerabilities fixed</summary>

*Sourced from The GitHub Security Advisory Database.*

> **High severity vulnerability that affects lodash, lodash-es, lodash-amd, lodash.template, lodash.merge, lodash.mergewith, and lodash.defaultsdeep**
> Affected versions of lodash are vulnerable to Prototype Pollution.
> The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
>
> Affected versions: < 4.5.0

</details>
<details>
<summary>Commits</summary>

- [`ab73503`](lodash/lodash@ab73503) Bump to v4.5.0.
- [`a4f7d4c`](lodash/lodash@a4f7d4c) Rebuild lodash and docs.
- [`cca5ac6`](lodash/lodash@cca5ac6) Fix npm-test by removing the call to test-docs.
- [`9f7f9fc`](lodash/lodash@9f7f9fc) Adjust heading order. [ci skip]
- [`6e2fb92`](lodash/lodash@6e2fb92) Remove unused `baseArity`.
- [`4f702e2`](lodash/lodash@4f702e2) Specify utf8 encoding.
- [`b188f90`](lodash/lodash@b188f90) Add fp tests for iteratee shorthands.
- [`7b93dc9`](lodash/lodash@7b93dc9) Ensure clone methods clone expando properties of boolean, number, & string ob...
- [`664d66a`](lodash/lodash@664d66a) Make string tests more consistent.
- [`d9dc0e6`](lodash/lodash@d9dc0e6) Add `_.invertBy` tests.
- Additional commits viewable in [compare view](lodash/lodash@4.4.0...4.5.0)
</details>
<br />

[![Dependabot compatibility score](https://api.dependabot.com/badges/compatibility_score?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)](https://dependabot.com/compatibility-score.html?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)

</details>
@bors
Copy link
Contributor

bors commented Jan 2, 2020

💥 Test timed out

@carols10cents
Copy link
Member

is it possible that there is something in the generated merge commit message that prevents TravisCI from running the build? 🤔

dependabot's PR description contains commits from lodash, like this one (emphasis mine):

  • 9f7f9fc Adjust heading order. [ci skip]

Travis has this issue: https://travis-ci.community/t/ci-skip-in-merge-commit-builds-previous-commit/1695

I'm going to try editing the PR description to remove that line and then rebasing/approving.

@carols10cents
Copy link
Member

@dependabot rebase

Bumps [lodash.template](https://github.com/lodash/lodash) from 4.4.0 to 4.5.0. **This update includes a security fix.**
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.4.0...4.5.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@carols10cents
Copy link
Member

@bors r+

@bors
Copy link
Contributor

bors commented Jan 3, 2020

📌 Commit be3bb2c has been approved by carols10cents

@bors
Copy link
Contributor

bors commented Jan 3, 2020

⌛ Testing commit be3bb2c with merge aadb307...

bors added a commit that referenced this pull request Jan 3, 2020
…te-4.5.0, r=carols10cents

[Security] Bump lodash.template from 4.4.0 to 4.5.0

Bumps [lodash.template](https://github.com/lodash/lodash) from 4.4.0 to 4.5.0. **This update includes a security fix.**
<details>
<summary>Vulnerabilities fixed</summary>

*Sourced from The GitHub Security Advisory Database.*

> **High severity vulnerability that affects lodash, lodash-es, lodash-amd, lodash.template, lodash.merge, lodash.mergewith, and lodash.defaultsdeep**
> Affected versions of lodash are vulnerable to Prototype Pollution.
> The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
>
> Affected versions: < 4.5.0

</details>
<details>
<summary>Commits</summary>

- [`ab73503`](lodash/lodash@ab73503) Bump to v4.5.0.
- [`a4f7d4c`](lodash/lodash@a4f7d4c) Rebuild lodash and docs.
- [`cca5ac6`](lodash/lodash@cca5ac6) Fix npm-test by removing the call to test-docs.
- [`6e2fb92`](lodash/lodash@6e2fb92) Remove unused `baseArity`.
- [`4f702e2`](lodash/lodash@4f702e2) Specify utf8 encoding.
- [`b188f90`](lodash/lodash@b188f90) Add fp tests for iteratee shorthands.
- [`7b93dc9`](lodash/lodash@7b93dc9) Ensure clone methods clone expando properties of boolean, number, & string ob...
- [`664d66a`](lodash/lodash@664d66a) Make string tests more consistent.
- [`d9dc0e6`](lodash/lodash@d9dc0e6) Add `_.invertBy` tests.
- Additional commits viewable in [compare view](lodash/lodash@4.4.0...4.5.0)
</details>
<br />

[![Dependabot compatibility score](https://api.dependabot.com/badges/compatibility_score?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)](https://dependabot.com/compatibility-score.html?dependency-name=lodash.template&package-manager=npm_and_yarn&previous-version=4.4.0&new-version=4.5.0)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language
- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language
- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language
- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language
- `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com):
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)

</details>
@bors
Copy link
Contributor

bors commented Jan 3, 2020

☀️ Test successful - checks-travis
Approved by: carols10cents
Pushing aadb307 to master...

@bors bors merged commit be3bb2c into master Jan 3, 2020
@dependabot-preview dependabot-preview bot deleted the dependabot/npm_and_yarn/lodash.template-4.5.0 branch January 3, 2020 02:54
@carols10cents
Copy link
Member

AHAHA HAHAHA HAHHHHH

@Turbo87
Copy link
Member

Turbo87 commented Jan 3, 2020

lol, nice work! 😅

@carols10cents
Copy link
Member

@Turbo87 thanks! And thank you for your comment, that's what helped me figure it out!!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security 🚨 Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

8 participants