Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump node-notifier from 8.0.2 to 10.0.0 in /ui #652

Merged
merged 1 commit into from
Jan 17, 2022

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 17, 2022

Bumps node-notifier from 8.0.2 to 10.0.0.

Changelog

Sourced from node-notifier's changelog.

v10.0.0

Breaking changes:

Setting NSAllowsArbitraryLoads as false for security reasons within terminal-notifier. Meaning non-https images/loads for terminal-notifier will no longer work. See #362

Fixes

  • fix: options.customPath doesn't work for windows toaster. See #373

v9.0.1

  • Fixes potential security issue with non-escaping input parameters for notify-send.

v9.0.0

Breaking changes:

  • Corrects mapping on snoretoast activate event. See #347.

Patches

  • Fix named pipe in WSL. See #342.
  • fixes possible injection issue for notify-send
Commits
  • 2c237b1 v10.0.0
  • 4b3af8b updates changelog
  • 1265ee3 chore: updates dependencies
  • b9427d4 Merge pull request #374 from mikaelbr/dependabot/npm_and_yarn/hosted-git-info...
  • 14af678 Merge pull request #362 from idhruvs/master
  • 4a4d25c Merge pull request #368 from mikaelbr/dependabot/npm_and_yarn/y18n-4.0.1
  • 61c02ce Bump lodash from 4.17.19 to 4.17.21 (#372)
  • c1b2e66 fix: options.customPath doesn't work for windows toaster (#373)
  • 85a7cc5 Bump hosted-git-info from 2.8.8 to 2.8.9
  • d66249d Bump y18n from 4.0.0 to 4.0.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript labels Jan 17, 2022
@dependabot dependabot bot requested a review from markphelps January 17, 2022 02:10
@codecov-commenter
Copy link

Codecov Report

Merging #652 (86f3aac) into master (dac9d22) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #652   +/-   ##
=======================================
  Coverage   83.43%   83.43%           
=======================================
  Files          16       16           
  Lines        1443     1443           
=======================================
  Hits         1204     1204           
  Misses        207      207           
  Partials       32       32           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update dac9d22...86f3aac. Read the comment docs.

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/ui/node-notifier-10.0.0 branch from 86f3aac to 1dd49e7 Compare January 17, 2022 16:23
@markphelps markphelps enabled auto-merge (squash) January 17, 2022 16:24
Bumps [node-notifier](https://github.com/mikaelbr/node-notifier) from 8.0.2 to 10.0.0.
- [Release notes](https://github.com/mikaelbr/node-notifier/releases)
- [Changelog](https://github.com/mikaelbr/node-notifier/blob/master/CHANGELOG.md)
- [Commits](mikaelbr/node-notifier@v8.0.2...v10.0.0)

---
updated-dependencies:
- dependency-name: node-notifier
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/ui/node-notifier-10.0.0 branch from 1dd49e7 to dc952d4 Compare January 17, 2022 16:26
@markphelps markphelps merged commit 6c1fbe2 into master Jan 17, 2022
@markphelps markphelps deleted the dependabot/npm_and_yarn/ui/node-notifier-10.0.0 branch January 17, 2022 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants