cli
cli copied to clipboard
chore(deps): bump semver and npm in /packages/cli-e2e/npm-shim
Removes semver. It's no longer used after updating ancestor dependency npm. These dependencies need to be updated together.
Removes semver
Updates npm from 9.3.0 to 9.9.2
Changelog
Sourced from npm's changelog.
9.9.2 (2023-11-14)
Bug Fixes
4c9a5e1#6993 look in workspace for exec commands (#6993) (@wraithgar)bb6f496#6992 correctly handle object licenses in SBOM generation (#6992) (@bdehamer,@jamietanna)10db3ca#6990 pkg: properly output in workspace mode (#6990) (@wraithgar)Documentation
Dependencies
9.9.1 (2023-10-30)
Bug Fixes
0dba79a#6942 add back bin/node-gyp-bin/node-gyp files (@lukekarrys)c93edb5#6932 add backbin/node-gyp-bin/node-gypfiles (@lukekarrys)Documentation
e6cce28#6925 use markdown links instead of html (@lukekarrys)9.9.0 (2023-10-06)
Features
ecda95a#6841 add npm sbom command (#6841) (@bdehamer)fdb8a86#6794 add package-lock-only mode to npm query (@wraithgar)16c04b1#6877 add no-package-lock mode to npm audit (@wraithgar)66ef765#6776 Add--cpuand--osoption to override platform specific install (#6776) (@yukukotani)Bug Fixes
c9406f7#6791 deprecate: ignore implicit workspace mode (#6758) (#6791) (@wraithgar)0b1d7c3#6779 allow searching packages with no description (#6779) (@wraithgar,@lukekarrys)Documentation
Dependencies
... (truncated)
Commits
ac75e7cchore: release 9.9.24c9a5e1fix: look in workspace for exec commands (#6993)bb6f496fix: correctly handle object licenses in SBOM generation (#6992)68e5cb6fix: split github workflow ref (#6991)10db3cafix(pkg): properly output in workspace mode (#6990)6ab06d7docs: update npm-prune description (#6985)6f9f0a1chore: release 9.9.1908ee54chore: add test flake improvements to windows shim tests0dba79afix: add back bin/node-gyp-bin/node-gyp filesc93edb5fix: add backbin/node-gyp-bin/node-gypfiles- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) -
@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) -
@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) -
@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency -
@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page.
Dependency Review
The following issues were found:- ✅ 0 vulnerable package(s)
- ❌ 1 package(s) with incompatible licenses
- ✅ 0 package(s) with invalid SPDX license definitions
- ⚠️ 4 package(s) with unknown licenses.
Snapshot Warnings
⚠️: No snapshots were found for the head SHA 51bb7d975dc3197a3124febef8217b7ed91e1053.Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.
License Issues
packages/cli-e2e/npm-shim/package-lock.json
| Package | Version | License | Issue Type |
| npm | 9.9.2 | Artistic-2.0 | Incompatible License |
| string-width-cjs | 4.2.3 | Null | Unknown License |
| strip-ansi-cjs | 6.0.1 | Null | Unknown License |
| wrap-ansi-cjs | 7.0.0 | Null | Unknown License |
packages/cli-e2e/npm-shim/package.json
| Package | Version | License | Issue Type |
| npm | ^9.9.2 | Null | Unknown License |
Allowed Licenses: 0BSD, Apache-2.0, Apache-2.0 AND MIT, Apache-2.0 AND BSD-3-Clause AND Python-2.0, Beerware, BlueOak-1.0.0, BSD-1-Clause, BSD-2-Clause, BSD-2-Clause-Patent, BSD-2-Clause-Views, BSD-2-Clause AND MIT, BSD-3-Clause, BSD-3-Clause-Attribution, BSD-3-Clause-Clear, BSL-1.0, CC-BY-3.0, CC-BY-4.0, CC0-1.0, CNRI-Python, curl, HPND, IBM-pibs, ImageMagick, ISC, JSON, MIT, MIT-0, MIT AND ISC, MIT AND Python-2.0, MIT-advertising, mpi-permissive, NCSA, ODC-By-1.0, PDDL-1.0, Plexus, PostgreSQL, PSF-2.0, Python-2.0, Python-2.0.1, SAX-PD, Unlicense, UPL-1.0, W3C, Wsuipa, WTFPL, X11, X11-distribute-modifications-variant, Xerox, Zlib, ZPL-2.1
Scanned Manifest Files
packages/cli-e2e/npm-shim/package-lock.json
- [email protected]
- [email protected]
- @isaacs/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @pkgjs/[email protected]
- @sigstore/[email protected]
- @sigstore/[email protected]
- @sigstore/[email protected]
- @sigstore/[email protected]
- @tufjs/[email protected]
- @tufjs/[email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- @gar/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- @npmcli/[email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- [email protected]
packages/cli-e2e/npm-shim/package.json
- npm@^9.9.2
- npm@^9.0.0