Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump ajv and pkg in /tools/clusterfuzz/js_fuzzer #34

Open
wants to merge 1 commit into
base: nw71
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Sep 7, 2022

Bumps ajv and pkg. These dependencies needed to be updated together.
Updates ajv from 6.12.0 to 6.12.6

Release notes

Sourced from ajv's releases.

v6.12.6

Fix performance issue of "url" format.

v6.12.5

Fix uri scheme validation (@​ChALkeR). Fix boolean schemas with strictKeywords option (#1270)

v6.12.4

Fix: coercion of one-item arrays to scalar that should fail validation (failing example).

v6.12.3

Pass schema object to processCode function Option for strictNumbers (@​issacgerges, #1128) Fixed vulnerability related to untrusted schemas (CVE-2020-15366)

v6.12.2

Removed post-install script

v6.12.1

Docs and dependency updates

Commits
  • fe59143 6.12.6
  • d580d3e Merge pull request #1298 from ajv-validator/fix-url
  • fd36389 fix: regular expression for "url" format
  • 490e34c docs: link to v7-beta branch
  • 9cd93a1 docs: note about v7 in readme
  • 877d286 Merge pull request #1262 from b4h0-c4t/refactor-opt-object-type
  • f1c8e45 6.12.5
  • 764035e Merge branch 'ChALkeR-chalker/fix-comma'
  • 3798160 Merge branch 'chalker/fix-comma' of git://github.com/ChALkeR/ajv into ChALkeR...
  • a3c7eba Merge branch 'refactor-opt-object-type' of github.com:b4h0-c4t/ajv into refac...
  • Additional commits viewable in compare view

Updates pkg from 4.3.4 to 4.5.1

Release notes

Sourced from pkg's releases.

4.5.1

  • Added documentation about NODE_OPTIONS: #996
  • Bootstrap: adjust for internalModuleReadJSON of newer Node.js: a20111e91d64c2380e4a10ce9a4a27848b427a5e
  • Bootstrap: support both old and new internalModuleReadJSON: 9598890350cc1d18672ddbc5032d142c4f019369
  • Chore: add ci, stale workflows and dependabot: #1074
  • Set up and run Prettier over entire codebase.: #1076
  • Drop dependabot.yml in favor of repo settings.: #1092
  • Remove incorrect \?\ prefix on windows and fs.promises fixes: #1095
  • Upgrade ESLint + move to eslint-config-airbnb-base.: #1088
  • Promisified exec and execFile should return a promise with ChildProcess instance attached: #880
  • Chore: make pkg-fetch dep static (temporarily).: #1100
  • Add pkg.outputPath as a configuration option.: #574

Credits

Huge thanks to @​SnakeDrak, @​robertsLando, @​hipstersmoothie, @​onip, and @​Symbitic for helping!

4.5.0

  • Branding change (#939)
  • Update badges in README (#949)
  • update tests test for node 14 CI (#977)
  • Bump lodash from 4.17.15 to 4.17.19 (#945)
  • Added environment var section on Readme (#684)
  • Add missing stat.isSocket (#720)
  • Fix configuration for node-notifier (#1021)
  • Add support for Node native addons (#837)
  • docs: MAKE_JOB_COUNT and PKG_IGNORE_TAG env var (#1053)
  • Bugfix for fs.readdir(), fs.readdirSync() (#992)
  • Replace deprecated assert.equal and assert.deepEqual. (#1063)
  • Update ZEIT to Vercel in package.json. (#1064)
  • Add cross-platform support for dot-node files. (#1066)
Commits
  • c332fbb 4.5.1
  • f08d083 Add pkg.outputPath as a configuration option. (#574)
  • 165fcd5 chore: make pkg-fetch dep static (temporarily). (#1100)
  • 9bb4f70 promisified exec and execFile should return a promise with ChildProcess insta...
  • e463acc Upgrade ESLint + move to eslint-config-airbnb-base. (#1088)
  • 1c219c8 Remove incorrect \?\ prefix on windows and fs.promises fixes (#1095)
  • 663f3f0 Drop dependabot.yml in favor of repo settings. (#1092)
  • ddf5217 Set up and run Prettier over entire codebase. (#1076)
  • 31e8bf7 chore: add ci, stale workflows and dependabot (#1074)
  • 9598890 bootstrap: support both old and new internalModuleReadJSON
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by leerobinson, a new releaser for pkg since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [ajv](https://github.com/ajv-validator/ajv) and [pkg](https://github.com/vercel/pkg). These dependencies needed to be updated together.

Updates `ajv` from 6.12.0 to 6.12.6
- [Release notes](https://github.com/ajv-validator/ajv/releases)
- [Commits](ajv-validator/ajv@v6.12.0...v6.12.6)

Updates `pkg` from 4.3.4 to 4.5.1
- [Release notes](https://github.com/vercel/pkg/releases)
- [Commits](vercel/pkg@4.3.4...4.5.1)

---
updated-dependencies:
- dependency-name: ajv
  dependency-type: indirect
- dependency-name: pkg
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Sep 7, 2022
@dependabot dependabot bot changed the base branch from nw68 to nw69 September 30, 2022 21:11
@dependabot dependabot bot changed the base branch from nw69 to nw71 December 8, 2022 21:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
0 participants