bulk-decaffeinate
bulk-decaffeinate copied to clipboard
chore(deps-dev): [security] bump semantic-release from 6.3.6 to 17.4.2
Bumps semantic-release from 6.3.6 to 17.4.2. This update includes a security fix.
Vulnerabilities fixed
Sourced from The GitHub Security Advisory Database.
Secret disclosure when containing characters that become URI encoded
Impact
Secrets that would normally be masked by
semantic-release
can be accidentally disclosed if they contain characters that become encoded when included in a URL.Patches
Fixed in v17.2.3
Workarounds
Secrets that do not contain characters that become encoded when included in a URL are already masked properly.
Affected versions: <= 17.2.2
Release notes
Sourced from semantic-release's releases.
v17.4.2
17.4.2 (2021-03-11)
Bug Fixes
v17.4.1
17.4.1 (2021-03-03)
Bug Fixes
v17.4.0
17.4.0 (2021-02-26)
Features
v17.3.9
17.3.9 (2021-02-12)
Bug Fixes
v17.3.8
17.3.8 (2021-02-08)
Bug Fixes
- deps: update dependency marked to v2 (a2eaed0)
v17.3.7
17.3.7 (2021-01-22)
Bug Fixes
v17.3.6
17.3.6 (2021-01-21)
... (truncated)
Commits
44b3344
fix(deps): update dependency hosted-git-info to v4 (#1838)046a845
chore(deps): lock file maintenance (#1835)48def0c
docs: fix links to gitlab releases documentation (#1834)2b6c9ba
docs: update documentation for addNote function (#1833)07f12b9
fix(deps): peer dependecy error withmarked-terminal
(#1829)2272ce3
chore(deps): lock file maintenance (#1826)3ecc196
feat(config): Use cosmiconfig defaults to support .cjs config files (#1815)acf8bc4
docs: fix missing whitespace (#1821)67dfb67
docs(README): change link to Angular's Contribution guidelines instead of Ang...f25c352
chore(deps): lock file maintenance (#1813)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language -
@dependabot badge me
will comment on this PR with code to add a "Dependabot enabled" badge to your readme
Additionally, you can set the following in your Dependabot dashboard:
- Update frequency (including time of day and day of week)
- Pull request limits (per update run and/or open at any time)
- Automerge options (never/patch/minor, and dev/runtime dependencies)
- Out-of-range updates (receive only lockfile updates, if desired)
- Security updates (receive only security updates, if desired)