Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[gypcrete] 更新漏洞套件 pt.1 #371

Merged
merged 50 commits into from
May 25, 2022
Merged

Conversation

kyoyadmoon
Copy link
Member

@kyoyadmoon kyoyadmoon commented May 24, 2022

Purpose

這是漏洞套件更新計畫 part 1
先將 dependabot 能夠自動產生 PR 的列出來,從中檢視確認沒有 breaking change 疑慮的 ,優先處理升級
有簡單在 storybook 把 component 都玩過一次,看起來沒有問題

Changes

build(deps): bump merge-deep from 3.0.2 to 3.0.3 (4371139)
build(deps): bump url-parse from 1.4.3 to 1.5.10 (8f45060)
build(deps): bump handlebars from 4.6.0 to 4.7.7 (064faa8)
build(deps): bump async from 2.6.0 to 2.6.4 (9b1d447)
build(deps): bump moment from 2.24.0 to 2.29.3 (07d4c98)
build(deps): bump tmpl from 1.0.4 to 1.0.5 (1e451aa)
build(deps): bump tar from 2.2.1 to 2.2.2 (d323db1)
build(deps): bump ua-parser-js from 0.7.18 to 0.7.31 (a637d76)
build(deps): bump ssri from 6.0.1 to 6.0.2 (fec9a05)
build(deps): bump lodash from 4.17.15 to 4.17.21 (650472d)
build(deps): bump pug-code-gen from 2.0.2 to 2.0.3 (888e04a)
build(deps): bump y18n from 3.2.1 to 3.2.2 (601f045)
build(deps): bump nested-object-assign from 1.0.3 to 1.0.4 (c18ac15)
build(deps): bump markdown-to-jsx from 6.10.3 to 6.11.4 (74cb75c)
build(deps): bump websocket-extensions from 0.1.3 to 0.1.4 (7fa1daa)
build(deps): bump elliptic from 6.4.0 to 6.5.4 (c25ff00)
build(deps): bump shelljs from 0.8.3 to 0.8.5 (0fd220d)
build(deps): bump trim-off-newlines from 1.0.1 to 1.0.3 (5fb0ff6)
build(deps): bump ws from 5.2.2 to 5.2.3 (bcdc676)
build(deps): bump path-parse from 1.0.6 to 1.0.7 (06b2f2e)
build(deps): bump hosted-git-info from 2.7.1 to 2.8.9 (648b90f)
build(deps): bump ini from 1.3.5 to 1.3.8 (e351eb4)
build(deps): bump https-proxy-agent from 2.2.1 to 2.2.4 (8d7f874)

Risk

Usually none, if you have any please write it here.

TODOs

  • Describe what should be done outside of this PR
  • Maybe in other PRs or some manual actions.

dependabot bot and others added 30 commits May 16, 2022 03:30
Bumps [merge-deep](https://github.com/jonschlinkert/merge-deep) from 3.0.2 to 3.0.3.
- [Release notes](https://github.com/jonschlinkert/merge-deep/releases)
- [Commits](jonschlinkert/merge-deep@3.0.2...3.0.3)

---
updated-dependencies:
- dependency-name: merge-deep
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [url-parse](https://github.com/unshiftio/url-parse) from 1.4.3 to 1.5.10.
- [Release notes](https://github.com/unshiftio/url-parse/releases)
- [Commits](unshiftio/url-parse@1.4.3...1.5.10)

---
updated-dependencies:
- dependency-name: url-parse
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [handlebars](https://github.com/wycats/handlebars.js) from 4.6.0 to 4.7.7.
- [Release notes](https://github.com/wycats/handlebars.js/releases)
- [Changelog](https://github.com/handlebars-lang/handlebars.js/blob/master/release-notes.md)
- [Commits](handlebars-lang/handlebars.js@v4.6.0...v4.7.7)

---
updated-dependencies:
- dependency-name: handlebars
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [async](https://github.com/caolan/async) from 2.6.0 to 2.6.4.
- [Release notes](https://github.com/caolan/async/releases)
- [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md)
- [Commits](caolan/async@v2.6.0...v2.6.4)

---
updated-dependencies:
- dependency-name: async
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [moment](https://github.com/moment/moment) from 2.24.0 to 2.29.3.
- [Release notes](https://github.com/moment/moment/releases)
- [Changelog](https://github.com/moment/moment/blob/2.29.3/CHANGELOG.md)
- [Commits](moment/moment@2.24.0...2.29.3)

---
updated-dependencies:
- dependency-name: moment
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tmpl](https://github.com/daaku/nodejs-tmpl) from 1.0.4 to 1.0.5.
- [Release notes](https://github.com/daaku/nodejs-tmpl/releases)
- [Commits](https://github.com/daaku/nodejs-tmpl/commits/v1.0.5)

---
updated-dependencies:
- dependency-name: tmpl
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [tar](https://github.com/npm/node-tar) from 2.2.1 to 2.2.2.
- [Release notes](https://github.com/npm/node-tar/releases)
- [Changelog](https://github.com/npm/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v2.2.1...v2.2.2)

---
updated-dependencies:
- dependency-name: tar
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ua-parser-js](https://github.com/faisalman/ua-parser-js) from 0.7.18 to 0.7.31.
- [Release notes](https://github.com/faisalman/ua-parser-js/releases)
- [Commits](faisalman/ua-parser-js@0.7.18...0.7.31)

---
updated-dependencies:
- dependency-name: ua-parser-js
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ssri](https://github.com/npm/ssri) from 6.0.1 to 6.0.2.
- [Release notes](https://github.com/npm/ssri/releases)
- [Changelog](https://github.com/npm/ssri/blob/v6.0.2/CHANGELOG.md)
- [Commits](npm/ssri@v6.0.1...v6.0.2)

---
updated-dependencies:
- dependency-name: ssri
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.15 to 4.17.21.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](lodash/lodash@4.17.15...4.17.21)

---
updated-dependencies:
- dependency-name: lodash
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [pug-code-gen](https://github.com/pugjs/pug) from 2.0.2 to 2.0.3.
- [Release notes](https://github.com/pugjs/pug/releases)
- [Commits](https://github.com/pugjs/pug/compare/pug-code-gen@2.0.2...pug@2.0.3)

---
updated-dependencies:
- dependency-name: pug-code-gen
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [y18n](https://github.com/yargs/y18n) from 3.2.1 to 3.2.2.
- [Release notes](https://github.com/yargs/y18n/releases)
- [Changelog](https://github.com/yargs/y18n/blob/master/CHANGELOG.md)
- [Commits](https://github.com/yargs/y18n/commits)

---
updated-dependencies:
- dependency-name: y18n
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [nested-object-assign](https://github.com/Geta/NestedObjectAssign) from 1.0.3 to 1.0.4.
- [Release notes](https://github.com/Geta/NestedObjectAssign/releases)
- [Commits](Geta/NestedObjectAssign@v1.0.3...v1.0.4)

---
updated-dependencies:
- dependency-name: nested-object-assign
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [markdown-to-jsx](https://github.com/probablyup/markdown-to-jsx) from 6.10.3 to 6.11.4.
- [Release notes](https://github.com/probablyup/markdown-to-jsx/releases)
- [Commits](quantizor/markdown-to-jsx@6.10.3...6.11.4)

---
updated-dependencies:
- dependency-name: markdown-to-jsx
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [websocket-extensions](https://github.com/faye/websocket-extensions-node) from 0.1.3 to 0.1.4.
- [Release notes](https://github.com/faye/websocket-extensions-node/releases)
- [Changelog](https://github.com/faye/websocket-extensions-node/blob/main/CHANGELOG.md)
- [Commits](faye/websocket-extensions-node@0.1.3...0.1.4)

---
updated-dependencies:
- dependency-name: websocket-extensions
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [elliptic](https://github.com/indutny/elliptic) from 6.4.0 to 6.5.4.
- [Release notes](https://github.com/indutny/elliptic/releases)
- [Commits](indutny/elliptic@v6.4.0...v6.5.4)

---
updated-dependencies:
- dependency-name: elliptic
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…-3.0.3

build(deps): bump merge-deep from 3.0.2 to 3.0.3
…1.5.10

build(deps): bump url-parse from 1.4.3 to 1.5.10
…-4.7.7

build(deps): bump handlebars from 4.6.0 to 4.7.7
build(deps): bump async from 2.6.0 to 2.6.4
…js-0.7.31

build(deps): bump ua-parser-js from 0.7.18 to 0.7.31
build(deps): bump ssri from 6.0.1 to 6.0.2
…into dependabot/npm_and_yarn/pug-code-gen-2.0.3
…7.21

build(deps): bump lodash from 4.17.15 to 4.17.21
…en-2.0.3

build(deps): bump pug-code-gen from 2.0.2 to 2.0.3
build(deps): bump moment from 2.24.0 to 2.29.3
build(deps): bump tmpl from 1.0.4 to 1.0.5
build(deps): bump tar from 2.2.1 to 2.2.2
@ichefbot ichefbot requested a review from brianwu291 May 24, 2022 12:18
@kyoyadmoon kyoyadmoon marked this pull request as draft May 24, 2022 12:54
dependabot bot and others added 10 commits May 24, 2022 12:54
Bumps [shelljs](https://github.com/shelljs/shelljs) from 0.8.3 to 0.8.5.
- [Release notes](https://github.com/shelljs/shelljs/releases)
- [Changelog](https://github.com/shelljs/shelljs/blob/master/CHANGELOG.md)
- [Commits](shelljs/shelljs@v0.8.3...v0.8.5)

---
updated-dependencies:
- dependency-name: shelljs
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [trim-off-newlines](https://github.com/stevemao/trim-off-newlines) from 1.0.1 to 1.0.3.
- [Release notes](https://github.com/stevemao/trim-off-newlines/releases)
- [Commits](stevemao/trim-off-newlines@v1.0.1...v1.0.3)

---
updated-dependencies:
- dependency-name: trim-off-newlines
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ws](https://github.com/websockets/ws) from 5.2.2 to 5.2.3.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@5.2.2...5.2.3)

---
updated-dependencies:
- dependency-name: ws
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [path-parse](https://github.com/jbgutierrez/path-parse) from 1.0.6 to 1.0.7.
- [Release notes](https://github.com/jbgutierrez/path-parse/releases)
- [Commits](https://github.com/jbgutierrez/path-parse/commits/v1.0.7)

---
updated-dependencies:
- dependency-name: path-parse
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [hosted-git-info](https://github.com/npm/hosted-git-info) from 2.7.1 to 2.8.9.
- [Release notes](https://github.com/npm/hosted-git-info/releases)
- [Changelog](https://github.com/npm/hosted-git-info/blob/v2.8.9/CHANGELOG.md)
- [Commits](npm/hosted-git-info@v2.7.1...v2.8.9)

---
updated-dependencies:
- dependency-name: hosted-git-info
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ini](https://github.com/npm/ini) from 1.3.5 to 1.3.8.
- [Release notes](https://github.com/npm/ini/releases)
- [Changelog](https://github.com/npm/ini/blob/main/CHANGELOG.md)
- [Commits](npm/ini@v1.3.5...v1.3.8)

---
updated-dependencies:
- dependency-name: ini
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [https-proxy-agent](https://github.com/TooTallNate/node-https-proxy-agent) from 2.2.1 to 2.2.4.
- [Release notes](https://github.com/TooTallNate/node-https-proxy-agent/releases)
- [Commits](TooTallNate/proxy-agents@2.2.1...2.2.4)

---
updated-dependencies:
- dependency-name: https-proxy-agent
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…ewlines-1.0.3

build(deps): bump trim-off-newlines from 1.0.1 to 1.0.3
build(deps): bump ws from 5.2.2 to 5.2.3
@github-actions github-actions bot temporarily deployed to canary May 24, 2022 15:29 Inactive
@github-actions github-actions bot temporarily deployed to canary May 24, 2022 15:29 Inactive
build(deps): bump ini from 1.3.5 to 1.3.8
@github-actions github-actions bot temporarily deployed to canary May 24, 2022 15:31 Inactive
…y-agent-2.2.4

build(deps): bump https-proxy-agent from 2.2.1 to 2.2.4
build(deps): bump shelljs from 0.8.3 to 0.8.5
…-1.0.7

build(deps): bump path-parse from 1.0.6 to 1.0.7
@github-actions github-actions bot temporarily deployed to canary May 24, 2022 15:33 Inactive
@github-actions github-actions bot temporarily deployed to canary May 24, 2022 15:34 Inactive
@github-actions github-actions bot temporarily deployed to canary May 24, 2022 15:35 Inactive
…-info-2.8.9

build(deps): bump hosted-git-info from 2.7.1 to 2.8.9
@github-actions github-actions bot temporarily deployed to canary May 24, 2022 15:37 Inactive
@kyoyadmoon kyoyadmoon marked this pull request as ready for review May 25, 2022 02:53
@kyoyadmoon kyoyadmoon requested a review from zhusee2 May 25, 2022 04:03
Copy link
Contributor

@zhusee2 zhusee2 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

升起來

@kyoyadmoon kyoyadmoon merged commit c3fc107 into develop May 25, 2022
@kyoyadmoon kyoyadmoon deleted the fix/dependabot-alert-pt1 branch May 25, 2022 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants