ember-mobiledoc-editor
ember-mobiledoc-editor copied to clipboard
chore(deps-dev): bump bower from 1.8.2 to 1.8.14
Bumps bower from 1.8.2 to 1.8.14.
Release notes
Sourced from bower's releases.
v1.8.12
- Properly bundle all dependencies of Bower within package
v1.8.10
- Security fixes for tar-fs dependency bower/bower#2576
- Security fixes for handlebars dependency bower/bower#2586
- Security fixes for ini dependency bower/bower#2589
v1.8.8
Fix security issue connected to extracting .tar.gz archives
This bug allows to write arbitrary file on filesystem when Bower extracts malicious package
Needlessly to say, please upgrade
v1.8.7
Fixes side effect of fix from v1.8.6 that caused improper permissions for extracted folders
v1.8.6
Fix Zip Slip Vulnerability of decompress-zip package: https://snyk.io/research/zip-slip-vulnerability
Note: v1.8.5 has been unpublished because of missing files
v1.8.4
- Fixes release 1.8.3 by publishing with npm@3 instead of npm@5 (to include
lib/node_modules
)v1.8.3
- 451c60e Do not store resolutions if --save is not used, fixes #2344 (#2508)
- 50ee729 Allow to disable shorthand resolver (#2507)
- bb17839 Allow shallow cloning when source is a ssh protocol (#2506)
- 5a6ae54 Add support for Arrays in Environment Variable replacement (#2411)
- 74af42c Only replace last
@
after (if any) last/
with#
(#2395)- 💯Make tests work on Windows / Linux / OSX on node versions 0.10 / 0.12 / 4 / 6 / 8 / 9
- 💅Format source code with prettier
Commits
d765b2b
Bump to 1.8.14ca23b46
Run CI only on node 6+7f26c5b
Fix bug unauthenticated git protocol in GitHubResolver (#2612)4b5722f
Update README.md557c1cd
Fix mode for bin/bower74560b7
Fix child process execution2905791
Fix running bower on non-windowsdfdda3f
Merge remote-tracking branch 'origin/master'fa36814
Bump to 1.8.13f19bc34
Make sure correct git/svn binary is always used- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by sheerun, a new releaser for bower since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)