drive-desktop
drive-desktop copied to clipboard
chore(deps): bump the npm_and_yarn group group in /release/app with 2 updates
Bumps the npm_and_yarn group group in /release/app with 2 updates: @rudderstack/rudder-sdk-node and axios.
Updates @rudderstack/rudder-sdk-node from 1.1.4 to 2.0.7
Release notes
Sourced from @rudderstack/rudder-sdk-node's releases.
2.0.7
Bug Fixes
2.0.6
Bug Fixes
- log level priority (#126) (96e1990)
- security vulnerabilities upgrade axios from 0.26.0 to 1.6.0 (#125) (83c18ff)
2.0.5
Bug Fixes
2.0.4
Bug Fixes
- concurrent event triggering unnecessary flush call (#113) (5dd8999)
- remove winston logger dependency to enable serverless environments (#112) (3619247)
2.0.3
Bug Fixes
v2.0.2
Fixes
- flush after a single event is sent
[#93](https://github.com/rudderlabs/rudder-sdk-node/issues/93)- added more loggers to assist in debugging
[#94](https://github.com/rudderlabs/rudder-sdk-node/issues/94)v2.0.1
Fixes
- library info override when provided in context
[#89](https://github.com/rudderlabs/rudder-sdk-node/issues/89)v2.0.0
Features
... (truncated)
Changelog
Sourced from @rudderstack/rudder-sdk-node's changelog.
2.0.7 (2024-01-29)
Bug Fixes
2.0.6 (2023-11-07)
Bug Fixes
- log level priority (#126) (96e1990)
- security vulnerabilities upgrade axios from 0.26.0 to 1.6.0 (#125) (83c18ff)
2.0.5 (2023-09-20)
Bug Fixes
2.0.4 (2023-08-28)
Bug Fixes
- concurrent event triggering unnecessary flush call (#113) (5dd8999)
- remove winston logger dependency to enable serverless environments (#112) (3619247)
2.0.3 (2023-06-30)
Bug Fixes
v2.0.2
Fixes
- flush after a single event is sent
[#93](https://github.com/rudderlabs/rudder-sdk-node/issues/93)- added more loggers to assist debugging
[#94](https://github.com/rudderlabs/rudder-sdk-node/issues/94)v2.0.1
Fixes
- library info override when provided in context
[#89](https://github.com/rudderlabs/rudder-sdk-node/issues/89)
... (truncated)
Commits
9121dbefix: update vulnerable packages (#135)6cdac1dchore(deps): bump msgpackr from 1.8.1 to 1.10.1 (#131)44bcb2fchore(deps): bump follow-redirects from 1.15.3 to 1.15.4 (#134)1da270aMerge pull request #128 from rudderlabs/masterbd618baMerge pull request #127 from rudderlabs/release/2.0.6256a998chore(release): 2.0.696e1990fix: log level priority (#126)83c18fffix: security vulnerabilities upgrade axios from 0.26.0 to 1.6.0 (#125)6fae212chore(deps-dev): bump@babel/traversefrom 7.17.3 to 7.23.2 (#124)b4a0268chore(deps-dev): bump postcss from 8.4.29 to 8.4.31 (#123)- Additional commits viewable in compare view
Updates axios from 0.26.0 to 1.6.5
Release notes
Sourced from axios's releases.
Release v1.6.5
Release notes:
Bug Fixes
- ci: refactor notify action as a job of publish action; (#6176) (0736f95)
- dns: fixed lookup error handling; (#6175) (f4f2b03)
Contributors to this release
Release v1.6.4
Release notes:
Bug Fixes
- security: fixed formToJSON prototype pollution vulnerability; (#6167) (3c0c11c)
- security: fixed security vulnerability in follow-redirects (#6163) (75af1cd)
Contributors to this release
Release v1.6.3
Release notes:
Bug Fixes
Contributors to this release
Release v1.6.2
Release notes:
Features
- withXSRFToken: added withXSRFToken option as a workaround to achieve the old
withCredentialsbehavior; (#6046) (cff9967)PRs
- feat(withXSRFToken): added withXSRFToken option as a workaround to achieve the old `withCredentials` behavior; ( #6046 )
📢 This PR added 'withXSRFToken' option as a replacement for old withCredentials behaviour. You should now use withXSRFToken along with withCredential to get the old behavior. This functionality is considered as a fix. </tr></table>
... (truncated)
Changelog
Sourced from axios's changelog.
1.6.5 (2024-01-05)
Bug Fixes
- ci: refactor notify action as a job of publish action; (#6176) (0736f95)
- dns: fixed lookup error handling; (#6175) (f4f2b03)
Contributors to this release
1.6.4 (2024-01-03)
Bug Fixes
- security: fixed formToJSON prototype pollution vulnerability; (#6167) (3c0c11c)
- security: fixed security vulnerability in follow-redirects (#6163) (75af1cd)
Contributors to this release
1.6.3 (2023-12-26)
Bug Fixes
Contributors to this release
1.6.2 (2023-11-14)
Features
- withXSRFToken: added withXSRFToken option as a workaround to achieve the old
withCredentialsbehavior; (#6046) (cff9967)PRs
- feat(withXSRFToken): added withXSRFToken option as a workaround to achieve the old `withCredentials` behavior; ( #6046 )
</tr></table>
... (truncated)
Commits
6d4c421chore(release): v1.6.5 (#6177)0736f95fix(ci): refactor notify action as a job of publish action; (#6176)f4f2b03fix(dns): fixed lookup error handling; (#6175)1f73dcbdocs: update sponsor links8790b8echore(release): v1.6.4 (#6173)0ad520dchore(ci): fix notify action; (#6172)3c0c11cfix(security): fixed formToJSON prototype pollution vulnerability; (#6167)75af1cdfix(security): fixed security vulnerability in follow-redirects (#6163)90864b3docs: update logos1542719docs: updated headline sponsors- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the Security Alerts page.
Quality Gate passed
Issues
0 New issues
Measures
0 Security Hotspots
No data about Coverage
0.0% Duplication on New Code
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.
To ignore these dependencies, configure ignore rules in dependabot.yml