Skip to content

[STUD-2684] Bump debug, karma and css-color-function#12

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/debug-and-karma-and-css-color-function-2.6.9
Open

[STUD-2684] Bump debug, karma and css-color-function#12
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/debug-and-karma-and-css-color-function-2.6.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 11, 2023

Copy link
Copy Markdown

Bumps debug to 2.6.9 and updates ancestor dependencies debug, karma and css-color-function. These dependencies need to be updated together.

Updates debug from 2.6.8 to 2.6.9

Release notes

Sourced from debug's releases.

2.6.9

Patches

  • Remove ReDoS regexp in %o formatter: #504

Credits

Huge thanks to @​zhuangya for their help!

Changelog

Sourced from debug's changelog.

2.6.9 / 2017-09-22

  • remove ReDoS regexp in %o formatter (#504)
Commits

Updates karma from 1.7.1 to 6.4.1

Release notes

Sourced from karma's releases.

v6.4.1

6.4.1 (2022-09-19)

Bug Fixes

v6.4.0

6.4.0 (2022-06-14)

Features

  • support SRI verification of link tags (dc51a2e)
  • support SRI verification of script tags (6a54b1c)

v6.3.20

6.3.20 (2022-05-13)

Bug Fixes

  • prefer IPv4 addresses when resolving domains (e17698f), closes #3730

v6.3.19

6.3.19 (2022-04-19)

Bug Fixes

  • client: error out when opening a new tab fails (099b85e)

v6.3.18

6.3.18 (2022-04-13)

Bug Fixes

  • deps: upgrade socket.io to v4.4.1 (52a30bb)

v6.3.17

6.3.17 (2022-02-28)

Bug Fixes

  • deps: update colors to maintained version (#3763) (fca1884)

v6.3.16

... (truncated)

Changelog

Sourced from karma's changelog.

6.4.1 (2022-09-19)

Bug Fixes

6.4.0 (2022-06-14)

Features

  • support SRI verification of link tags (dc51a2e)
  • support SRI verification of script tags (6a54b1c)

6.3.20 (2022-05-13)

Bug Fixes

  • prefer IPv4 addresses when resolving domains (e17698f), closes #3730

6.3.19 (2022-04-19)

Bug Fixes

  • client: error out when opening a new tab fails (099b85e)

6.3.18 (2022-04-13)

Bug Fixes

  • deps: upgrade socket.io to v4.4.1 (52a30bb)

6.3.17 (2022-02-28)

Bug Fixes

  • deps: update colors to maintained version (#3763) (fca1884)

6.3.16 (2022-02-10)

Bug Fixes

  • security: mitigate the "Open Redirect Vulnerability" (ff7edbb)

... (truncated)

Commits
  • 0013121 chore(release): 6.4.1 [skip ci]
  • 63d86be fix: pass integrity value
  • 84f7cc3 chore(release): 6.4.0 [skip ci]
  • f2d0663 docs: add integrity parameter
  • dc51a2e feat: support SRI verification of link tags
  • 6a54b1c feat: support SRI verification of script tags
  • 5e71cf5 chore(release): 6.3.20 [skip ci]
  • e17698f fix: prefer IPv4 addresses when resolving domains
  • 60f4f79 build: add Node 16 and 18 to the CI matrix
  • 6ff5aaf chore(release): 6.3.19 [skip ci]
  • Additional commits viewable in compare view

Updates css-color-function from 1.3.0 to 1.3.3

Release notes

Sourced from css-color-function's releases.

1.3.3

Bug fixes

  • #33 Reverts changes merged in #19 for for this non-breaking minor release. Fixes #32

1.3.2

⚠️ THIS INCLUDES BREAKING CHANGES If you need the 1.x series, use 1.3.3. We inadvertently releases breaking changes made in #19 in this 1.x release. Those changes are in the 2.x series. See #33 for more info.

Bug fixes

  • #31 Updates to latest version of debug package. Fixes #30

1.3.1

⚠️ THIS INCLUDES BREAKING CHANGES If you need the 1.x series, use 1.3.3. We inadvertently releases breaking changes made in #19 in this 1.x release. Those changes are in the 2.x series. See #33 for more info.

Bug fixes

  • #26 Fixes Tint, Shade, and Contrast Alpha Interference Issue.
Changelog

Sourced from css-color-function's changelog.

1.3.3 - October 7, 2017

  • REVERT RELEASE: This removes the changes made in [#19](https://github.com/ianstormtaylor/css-color-function/issues/19) only for this release. Those changes will be added back and released in a 2.0 because they are breaking changes.

1.3.2 - October 4, 2017

  • WARNING: This contains a breaking change in #19. If you need the 1.x series, use 1.3.3. Otherwise, use the 2.x series.
  • Fixes Vulnerability - Regular Expression Denial of Service caused by debug package. [#31](https://github.com/ianstormtaylor/css-color-function/issues/31)

1.3.1 - July 14, 2017

  • WARNING: This contains a breaking change in #19. If you need the 1.x series, use 1.3.3. Otherwise, use the 2.x series.
  • Fixes Tint, Shade, and Contrast Alpha Interference Issue. [#26](https://github.com/ianstormtaylor/css-color-function/issues/26)
Commits
Maintainer changes

This version was pushed to npm by thegaw, a new releaser for css-color-function since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jan 11, 2023
@aviary2-wf

aviary2-wf commented Jan 11, 2023

Copy link
Copy Markdown

Security Insights

The items listed below may not capture all security relevant changes. Before providing a security review, be sure to review the entire PR for security impact.

(1) Security relevant changes were detected
  • Watched keyword "sha1- in package-lock.json line(s) ['8645', '8651', '8657', '8669', '8678', '8690', '8699', '8711', '8724', '8740', '8749', '8763', '8781', '8787', '17349'] added
  • Action Items

    • Obtain a security review; reviewer should pay special attention to insights listed above
    • Verify aviary.yaml coverage of security relevant code

    Questions or Comments? Reach out on Slack: #support-infosec.

    Bumps [debug](https://github.com/debug-js/debug) to 2.6.9 and updates ancestor dependencies [debug](https://github.com/debug-js/debug), [karma](https://github.com/karma-runner/karma) and [css-color-function](https://github.com/ianstormtaylor/css-color-function). These dependencies need to be updated together.
    
    
    Updates `debug` from 2.6.8 to 2.6.9
    - [Release notes](https://github.com/debug-js/debug/releases)
    - [Changelog](https://github.com/debug-js/debug/blob/2.6.9/CHANGELOG.md)
    - [Commits](debug-js/debug@2.6.8...2.6.9)
    
    Updates `karma` from 1.7.1 to 6.4.1
    - [Release notes](https://github.com/karma-runner/karma/releases)
    - [Changelog](https://github.com/karma-runner/karma/blob/master/CHANGELOG.md)
    - [Commits](karma-runner/karma@1.7.1...v6.4.1)
    
    Updates `css-color-function` from 1.3.0 to 1.3.3
    - [Release notes](https://github.com/ianstormtaylor/css-color-function/releases)
    - [Changelog](https://github.com/ianstormtaylor/css-color-function/blob/master/History.md)
    - [Commits](ianstormtaylor/css-color-function@1.3.0...1.3.3)
    
    ---
    updated-dependencies:
    - dependency-name: debug
      dependency-type: indirect
    - dependency-name: karma
      dependency-type: direct:development
    - dependency-name: css-color-function
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <support@github.com>
    @dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/debug-and-karma-and-css-color-function-2.6.9 branch from 61831da to f9dfa83 Compare March 22, 2023 15:26
    @waynepaffhausen-wk waynepaffhausen-wk changed the title Bump debug, karma and css-color-function [STUD-2684] Bump debug, karma and css-color-function Mar 22, 2023
    Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

    Labels

    dependencies Pull requests that update a dependency file

    Projects

    None yet

    Development

    Successfully merging this pull request may close these issues.

    1 participant