Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update all non-major dependencies with stable version (patch) #1294

Merged
merged 1 commit into from
Sep 7, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 7, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update
@kong/kongponents (source) ^8.84.0 -> ^8.84.8 age adoption passing confidence peerDependencies patch
@semantic-release/changelog ^6.0.2 -> ^6.0.3 age adoption passing confidence devDependencies patch
eslint-plugin-promise ^4.2.1 -> ^4.3.1 age adoption passing confidence devDependencies patch
eslint-plugin-standard ^4.0.0 -> ^4.0.2 age adoption passing confidence devDependencies patch
node >=16.19.0 -> >=v16.19.1 age adoption passing confidence engines patch
yarn 1.22.17 -> 1.22.19 age adoption passing confidence volta patch

Release Notes

Kong/kongponents (@​kong/kongponents)

v8.84.8

Compare Source

Bug Fixes
  • KTruncate, KMultiselect: add fix for ResizeObserver [KHCP-7734] (#​1508) (ea47855)

v8.84.7

Compare Source

Bug Fixes

v8.84.6

Compare Source

Bug Fixes

v8.84.5

Compare Source

Bug Fixes

v8.84.4

Compare Source

Bug Fixes

v8.84.3

Compare Source

Bug Fixes

v8.84.2

Compare Source

Bug Fixes

v8.84.1

Compare Source

Bug Fixes
nodejs/node (node)

v16.19.1: 2023-02-16, Version 16.19.1 'Gallium' (LTS), @​richardlau

Compare Source

This is a security release.

Notable Changes

The following CVEs are fixed in this release:

  • CVE-2023-23918: Node.js Permissions policies can be bypassed via process.mainModule (High)
  • CVE-2023-23919: Node.js OpenSSL error handling issues in nodejs crypto library (Medium)
  • CVE-2023-23920: Node.js insecure loading of ICU data through ICU_DATA environment variable (Low)

Fixed by an update to undici:

More detailed information on each of the vulnerabilities can be found in February 2023 Security Releases blog post.

This security release includes OpenSSL security updates as outlined in the recent
OpenSSL security advisory.

Commits
yarnpkg/yarn (yarn)

v1.22.19

Compare Source

  • Adds compatibility with WebAuthn on the npm registry

v1.22.18

Compare Source

Node 17.7.0 had a regression in url.resolve which broke Yarn, causing network errors. This release fixes that, although the regression also got fixed on the Node side starting from 17.7.1, so as long as you keep your Node up-to-date it'll be fine.


Configuration

📅 Schedule: Branch creation - "every weekday" in timezone America/New_York, Automerge - "every weekday" in timezone America/New_York.

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added dependencies Pull requests that update a dependency file renovate-bot labels Sep 7, 2023
@renovate renovate bot enabled auto-merge (squash) September 7, 2023 20:11
@renovate renovate bot force-pushed the renovate/patch-all-minor-patch branch from 568533c to 5aa9532 Compare September 7, 2023 20:19
@renovate renovate bot merged commit a4d52e9 into main Sep 7, 2023
3 checks passed
@renovate renovate bot deleted the renovate/patch-all-minor-patch branch September 7, 2023 20:22
@kongponents-bot
Copy link
Collaborator

🎉 This PR is included in version 2.8.8 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file released renovate-bot
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant