Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Snyk fix eb113e9bbaa90fcd32875339c15f81c1 #615

Open
wants to merge 39 commits into
base: master
Choose a base branch
from

Conversation

Say383
Copy link

@Say383 Say383 commented Apr 10, 2023

No description provided.

snyk-bot and others added 30 commits March 29, 2023 23:38
…e16587

[Snyk] Security upgrade python from 2 to 3.12.0a5
…e16587

[Snyk] Security upgrade python from 2 to 3.12.0a5
Bumps [protobufjs](https://github.com/protobufjs/protobuf.js) from 6.10.2 to 6.11.3.
- [Release notes](https://github.com/protobufjs/protobuf.js/releases)
- [Changelog](https://github.com/protobufjs/protobuf.js/blob/v6.11.3/CHANGELOG.md)
- [Commits](protobufjs/protobuf.js@v6.10.2...v6.11.3)

---
updated-dependencies:
- dependency-name: protobufjs
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ansi-regex](https://github.com/chalk/ansi-regex) from 4.1.0 to 4.1.1.
- [Release notes](https://github.com/chalk/ansi-regex/releases)
- [Commits](chalk/ansi-regex@v4.1.0...v4.1.1)

---
updated-dependencies:
- dependency-name: ansi-regex
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…tobufjs-6.11.3

Bump protobufjs from 6.10.2 to 6.11.3 in /octokit
Bumps [minimist](https://github.com/minimistjs/minimist) from 1.2.5 to 1.2.8.
- [Release notes](https://github.com/minimistjs/minimist/releases)
- [Changelog](https://github.com/minimistjs/minimist/blob/main/CHANGELOG.md)
- [Commits](minimistjs/minimist@v1.2.5...v1.2.8)

---
updated-dependencies:
- dependency-name: minimist
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [node-forge](https://github.com/digitalbazaar/forge) and [google-p12-pem](https://github.com/googleapis/google-p12-pem). These dependencies needed to be updated together.

Updates `node-forge` from 0.10.0 to 1.3.1
- [Release notes](https://github.com/digitalbazaar/forge/releases)
- [Changelog](https://github.com/digitalbazaar/forge/blob/main/CHANGELOG.md)
- [Commits](digitalbazaar/forge@0.10.0...v1.3.1)

Updates `google-p12-pem` from 3.0.3 to 3.1.4
- [Release notes](https://github.com/googleapis/google-p12-pem/releases)
- [Changelog](https://github.com/googleapis/google-p12-pem/blob/main/CHANGELOG.md)
- [Commits](googleapis/google-p12-pem@v3.0.3...v3.1.4)

---
updated-dependencies:
- dependency-name: node-forge
  dependency-type: indirect
- dependency-name: google-p12-pem
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…55e3da2

[Snyk] Security upgrade openjdk from 8-jdk to 16.0.2-jdk
…i-regex-4.1.1

Bump ansi-regex from 4.1.0 to 4.1.1 in /octokit
…de-forge-and-google-p12-pem-1.3.1

Bump node-forge and google-p12-pem in /octokit
Bumps [node-fetch](https://github.com/node-fetch/node-fetch) from 2.6.1 to 2.6.9.
- [Release notes](https://github.com/node-fetch/node-fetch/releases)
- [Commits](node-fetch/node-fetch@v2.6.1...v2.6.9)

---
updated-dependencies:
- dependency-name: node-fetch
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…de-fetch-2.6.9

Bump node-fetch from 2.6.1 to 2.6.9 in /octokit
Bumps [werkzeug](https://github.com/pallets/werkzeug) from 0.16.1 to 2.2.3.
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@0.16.1...2.2.3)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…imist-1.2.8

Bump minimist from 1.2.5 to 1.2.8 in /octokit
Bump werkzeug from 0.16.1 to 2.2.3 in /airflow
Removes [got](https://github.com/sindresorhus/got). It's no longer used after updating ancestor dependency [nodemon](https://github.com/remy/nodemon). These dependencies need to be updated together.


Removes `got`

Updates `nodemon` from 2.0.6 to 2.0.22
- [Release notes](https://github.com/remy/nodemon/releases)
- [Commits](remy/nodemon@v2.0.6...v2.0.22)

---
updated-dependencies:
- dependency-name: got
  dependency-type: indirect
- dependency-name: nodemon
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
…-and-nodemon--removed

Bump got and nodemon in /octokit
Bumps [minimatch](https://github.com/isaacs/minimatch) from 3.0.4 to 3.1.2.
- [Release notes](https://github.com/isaacs/minimatch/releases)
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v3.0.4...v3.1.2)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [jsonwebtoken](https://github.com/auth0/node-jsonwebtoken) and [universal-github-app-jwt](https://github.com/gr2m/universal-github-app-jwt). These dependencies needed to be updated together.

Updates `jsonwebtoken` from 8.5.1 to 9.0.0
- [Release notes](https://github.com/auth0/node-jsonwebtoken/releases)
- [Changelog](https://github.com/auth0/node-jsonwebtoken/blob/master/CHANGELOG.md)
- [Commits](auth0/node-jsonwebtoken@v8.5.1...v9.0.0)

Updates `universal-github-app-jwt` from 1.1.0 to 1.1.1
- [Release notes](https://github.com/gr2m/universal-github-app-jwt/releases)
- [Commits](gr2m/universal-github-app-jwt@v1.1.0...v1.1.1)

---
updated-dependencies:
- dependency-name: jsonwebtoken
  dependency-type: indirect
- dependency-name: universal-github-app-jwt
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…nwebtoken-and-universal-github-app-jwt-9.0.0

Bump jsonwebtoken and universal-github-app-jwt in /octokit
…imatch-3.1.2

Bump minimatch from 3.0.4 to 3.1.2 in /octokit
…28f2516

[Snyk] Security upgrade alpine from 3.9 to 3.14
Say383 and others added 9 commits April 1, 2023 16:28
…5f62e20

[Snyk] Security upgrade frolvlad/alpine-glibc from latest to alpine-3.17_glibc-2.34
…4b660c2ceb7

[Snyk] Upgrade @octokit/auth-token from 2.4.4 to 2.5.0
Snyk has created this PR to upgrade express from 4.17.1 to 4.18.2.

See this package in npm:


See this project in Snyk:
https://app.snyk.io/org/say383/project/dee47398-9073-41fd-bd62-e8fc6c799974?utm_source=github&utm_medium=referral&page=upgrade-pr
…5ba544e

[Snyk] Security upgrade openjdk from 8 to 17.0.2
…7855136

[Snyk] Security upgrade jest from 23.6.0 to 24.0.0
…16a18dc7cbe

[Snyk] Upgrade express from 4.17.1 to 4.18.2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants