angular-safeguard
angular-safeguard copied to clipboard
Bump async and gh-pages
Bumps async to 2.6.4 and updates ancestor dependency gh-pages. These dependencies need to be updated together.
Updates async
from 2.6.1 to 2.6.4
Changelog
Sourced from async's changelog.
v2.6.4
- Fix potential prototype pollution exploit (#1828)
v2.6.3
- Updated lodash to squelch a security warning (#1675)
v2.6.2
- Updated lodash to squelch a security warning (#1620)
Commits
c6bdaca
Version 2.6.48870da9
Update built files4df6754
update changelog8f7f903
Fix prototype pollution vulnerability (#1828)f1d8383
Version 2.6.32b674c1
update changelogeab740f
fix: udpate lodash. closes #1675eaf32be
Version 2.6.2684b42e
Update built filese1bd3da
update changelog- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by hargasinski, a new releaser for async since your current version.
Updates gh-pages
from 1.2.0 to 4.0.0
Release notes
Sourced from gh-pages's releases.
v4.0.0
This release doesn't include any breaking changes, but due to updated development dependencies, tests are no longer run on Node 10.
What's Changed
- Bump minimist from 1.2.5 to 1.2.6 by
@dependabot
in tschaub/gh-pages#423- Bump async from 2.6.1 to 2.6.4 by
@dependabot
in tschaub/gh-pages#427- Bump path-parse from 1.0.6 to 1.0.7 by
@dependabot
in tschaub/gh-pages#431- Bump ansi-regex from 3.0.0 to 3.0.1 by
@dependabot
in tschaub/gh-pages#430- Updated dev dependencies and formatting by
@tschaub
in tschaub/gh-pages#432Full Changelog: https://github.com/tschaub/gh-pages/compare/v3.2.3...v4.0.0
v3.2.3
- #398 - Update glob-parent (
@tschaub
)- #395 - Switch from filenamify-url to filenamify (
@tw0517tw
)v3.0.0
Breaking changes:
None really. But tests are no longer run on Node < 10. Development dependencies were updated to address security warnings, and this meant tests could no longer be run on Node 6 or 8. If you still use these Node versions, you may still be able to use this library, but be warned that tests are no longer run on these versions.
All changes:
- #357 - Dev dependency updates (
@tschaub
)- #333 - Update readme with command line options (
@Victoire44
)- #356 - Test as a GitHub action (
@tschaub
)- #355 - feat(beforeAdd): allow custom script before git add (
@Xiphe
)- #336 - Fix remove not working properly (
@sunghwan2789
)- #328 - Update .travis.yml (
@XhmikosR
)- #327 - Fix typo (
@d-tsuji
)v2.2.0
- #318 - Allow an absolute path as dist directory (
@okuryu
)- #319 - Added 'remove' documentation to the readme (
@Sag-Dev
)- #323 - Update dependencies (
@tschaub
)- #277 - Add
--no-history
flag not to preserve deploy history (@dplusic
)v2.1.1
v2.1.0
- #307 - Dev dependency updates (
@tschaub
)- #303 - Support '--git' CLI option (
@JRJurman
)v2.0.1
- #268 - Continue even if no git configured user.
v2.0.0
Breaking changes:
... (truncated)
Changelog
Sourced from gh-pages's changelog.
v4.0.0
This release doesn't include any breaking changes, but due to updated development dependencies, tests are no longer run on Node 10.
- #432 - Updated dev dependencies and formatting (
@tschaub
)- #430 - Bump ansi-regex from 3.0.0 to 3.0.1 (
@tschaub
)- #431 - Bump path-parse from 1.0.6 to 1.0.7 (
@tschaub
)- #427 - Bump async from 2.6.1 to 2.6.4 (
@tschaub
)- #423 - Bump minimist from 1.2.5 to 1.2.6 (
@tschaub
)v3.2.3
- #398 - Update glob-parent (
@tschaub
)- #395 - Switch from filenamify-url to filenamify (
@tw0517tw
)v3.2.2
v3.2.1
v3.2.0
This release updates a few development dependencies and adds a bit of documentation.
- #391 - Update dev dependencies (
@tschaub
)- #375 - Add note about domain problem (
@demee
)- #390 - Fix little typo in the README (
@cizordj
)- #388 - Bump hosted-git-info from 2.8.8 to 2.8.9 (
@tschaub
)- #387 - Bump y18n from 4.0.0 to 4.0.3 (
@tschaub
)- #378 - Add GitHub Actions tips to readme.md (
@mickelsonmichael
)- #386 - Bump lodash from 4.17.14 to 4.17.21 (
@tschaub
)v3.1.0
The cache directory used by
gh-pages
is nownode_modules/.cache/gh-pages
. If you want to use a different location, set theCACHE_DIR
environment variable.v3.0.0
Breaking changes:
None really. But tests are no longer run on Node < 10. Development dependencies were updated to address security warnings, and this meant tests could no longer be run on Node 6 or 8. If you still use these Node versions, you may still be able to use this library, but be warned that tests are no longer run on these versions.
All changes:
... (truncated)
Commits
ef1c90d
4.0.0147a527
Log changescdb8820
Merge pull request #432 from tschaub/updatesd66679c
Stop testing on Node 104430720
Updated dev dependencies and formatting75809af
Merge pull request #430 from tschaub/dependabot/npm_and_yarn/ansi-regex-3.0.100fc968
Bump ansi-regex from 3.0.0 to 3.0.12b108cb
Merge pull request #431 from tschaub/dependabot/npm_and_yarn/path-parse-1.0.7c6f6b68
Bump path-parse from 1.0.6 to 1.0.79ac413b
Merge pull request #427 from tschaub/dependabot/npm_and_yarn/async-2.6.4- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.