Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

staging version 1.9.2491 #456

Merged
merged 132 commits into from
Mar 18, 2024
Merged

staging version 1.9.2491 #456

merged 132 commits into from
Mar 18, 2024

Conversation

suculent
Copy link
Owner

@suculent suculent commented Nov 9, 2023

No description provided.

dependabot bot and others added 30 commits May 24, 2023 00:34
Bumps [socket.io-parser](https://github.com/socketio/socket.io-parser) from 4.2.1 to 4.2.3.
- [Release notes](https://github.com/socketio/socket.io-parser/releases)
- [Changelog](https://github.com/socketio/socket.io-parser/blob/main/CHANGELOG.md)
- [Commits](socketio/socket.io-parser@4.2.1...4.2.3)

---
updated-dependencies:
- dependency-name: socket.io-parser
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [semver](https://github.com/npm/node-semver) from 7.3.7 to 7.5.2.
- [Release notes](https://github.com/npm/node-semver/releases)
- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md)
- [Commits](npm/node-semver@v7.3.7...v7.5.2)

---
updated-dependencies:
- dependency-name: semver
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [word-wrap](https://github.com/jonschlinkert/word-wrap) from 1.2.3 to 1.2.4.
- [Release notes](https://github.com/jonschlinkert/word-wrap/releases)
- [Commits](jonschlinkert/word-wrap@1.2.3...1.2.4)

---
updated-dependencies:
- dependency-name: word-wrap
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…io-and-socket.io-6.4.2

Bump engine.io and socket.io
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.0.0-20220531201128-c960675eff93 to 0.17.0.
- [Commits](https://github.com/golang/net/commits/v0.17.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [get-func-name](https://github.com/chaijs/get-func-name) from 2.0.0 to 2.0.2.
- [Release notes](https://github.com/chaijs/get-func-name/releases)
- [Commits](https://github.com/chaijs/get-func-name/commits/v2.0.2)

---
updated-dependencies:
- dependency-name: get-func-name
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps gopkg.in/yaml.v3 from 3.0.0-20200313102051-9f266ea9e77c to 3.0.0.

---
updated-dependencies:
- dependency-name: gopkg.in/yaml.v3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.47.0 to 1.56.3.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](grpc/grpc-go@v1.47.0...v1.56.3)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…io-parser-4.2.3

Bump socket.io-parser from 4.2.1 to 4.2.3
Bumps [@babel/traverse](https://github.com/babel/babel/tree/HEAD/packages/babel-traverse) from 7.20.12 to 7.23.2.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.23.2/packages/babel-traverse)

---
updated-dependencies:
- dependency-name: "@babel/traverse"
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…3252b59979bc04

[Snyk] Upgrade @snyk/protect from 1.1087.0 to 1.1185.0
…cc486088c12ea8

[Snyk] Upgrade mime from 1.6.0 to 3.0.0
…ap-1.2.4

Bump word-wrap from 1.2.3 to 1.2.4
…61645d916c

[Snyk] Security upgrade crypto-js from 4.1.1 to 4.2.0
…broker/goauth/golang.org/x/net-0.17.0

Bump golang.org/x/net from 0.0.0-20220531201128-c960675eff93 to 0.17.0 in /services/broker/goauth
…c-name-2.0.2

Bump get-func-name from 2.0.0 to 2.0.2
…broker/goauth/gopkg.in/yaml.v3-3.0.0

Bump gopkg.in/yaml.v3 from 3.0.0-20200313102051-9f266ea9e77c to 3.0.0 in /services/broker/goauth
…broker/goauth/google.golang.org/grpc-1.56.3

Bump google.golang.org/grpc from 1.47.0 to 1.56.3 in /services/broker/goauth
…raverse-7.23.2

Bump @babel/traverse from 7.20.12 to 7.23.2
* 'master' of github.com:suculent/thinx-device-api: (35 commits)
  Bump @babel/traverse from 7.20.12 to 7.23.2
  Bump google.golang.org/grpc in /services/broker/goauth
  Bump gopkg.in/yaml.v3 in /services/broker/goauth
  Bump get-func-name from 2.0.0 to 2.0.2
  Bump golang.org/x/net in /services/broker/goauth
  fix: package.json & package-lock.json to reduce vulnerabilities
  Bump word-wrap from 1.2.3 to 1.2.4
  feat: upgrade mime from 1.6.0 to 3.0.0
  fix: upgrade @snyk/protect from 1.1087.0 to 1.1185.0
  Bump semver from 7.3.7 to 7.5.2
  Bump socket.io-parser from 4.2.1 to 4.2.3
  Bump engine.io and socket.io
  Bump yaml from 2.1.0 to 2.2.2
  oversight fix redeploy
  one-off error?
  minor refactoring in apikeys (removing unused params, fixing arg type in one case)
  improved apikeys debug
  queue logic fix
  console debugging in broken API Key creation
  debugging API Key create issue (with one possible fix)
  ...
* main: (49 commits)
  maintenance release v1.9.2451
  removed services/broker submodule before re-adding
  removed lua-iinspect
  log leak fix
  log cleanup, redeploy after changing expired Rollbar Project Access Tokens
  submodule sync
  version bump, log cleanup and base image update after fixing GitHub OAuth
  dependency updates, fixing github login (has code but different object structure)
  test passes, but parsing fails
  spec fix for staging
  fails in tests, because code is B
  removed json
  fixes
  gpg
  debugging broken github-oauth login
  task renamed
  recent test passed, build stable, adding debug logging only for next refactoring steps
  fix for potent. unlinked github login addRoutes
  recent test passed, build stable, adding debug logging only for next refactoring steps
  github fix
  ...

# Conflicts:
#	package-lock.json
#	package.json
…r-js

Fix CVE CVE–2022–25927 ua parser js
suculent and others added 29 commits November 16, 2023 18:36
… upgrade will probably require rewriting the implementation
…aging

* commit '752ba34bf52dfb1bca23203a1d9f3e388e2b1c27':
  fix: package.json & package-lock.json to reduce vulnerabilities

# Conflicts:
#	package-lock.json
#	package.json
@suculent suculent merged commit 4fe932d into main Mar 18, 2024
8 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants