Skip to content

Conversation

@pull
Copy link

@pull pull bot commented Jan 12, 2022

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull bot added the ⤵️ pull label Jan 12, 2022
@guardrails
Copy link

guardrails bot commented Jan 12, 2022

⚠️ We detected 3 security issues in this pull request:

Mode: paranoid | Total findings: 3 | Considered vulnerability: 3

Vulnerable Libraries (3)
Severity Details
High [email protected] (t) upgrade to: >=3.5.0
Medium [email protected] (t) upgrade to: >24.9.0
Medium [email protected] (t) upgrade to: >0.5.1

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

dependabot bot and others added 18 commits June 1, 2022 07:49
Bumps [async](https://github.com/caolan/async) from 2.6.3 to 2.6.4.
- [Release notes](https://github.com/caolan/async/releases)
- [Changelog](https://github.com/caolan/async/blob/v2.6.4/CHANGELOG.md)
- [Commits](caolan/async@v2.6.3...v2.6.4)

---
updated-dependencies:
- dependency-name: async
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [node-fetch](https://github.com/node-fetch/node-fetch) from 2.6.6 to 2.6.7.
- [Release notes](https://github.com/node-fetch/node-fetch/releases)
- [Commits](node-fetch/node-fetch@v2.6.6...v2.6.7)

---
updated-dependencies:
- dependency-name: node-fetch
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- @semantic-release/exec - https://github.com/semantic-release/exec/releases
  - 6.x.x: node-version: the minimum required version of node is now v14.17
  - 5.x.x: Require Node.js >= 10.18
  - 4.x.x: Require Node.js >= 10.13

- semantic-release - https://github.com/semantic-release/semantic-release/releases
  - 19.x.x: node v15 has been removed from our defined supported versions of node
  - 18.x.x: node-version: the minimum required version of node is now v14.17
- gulp-awspublish - https://github.com/pgherveou/gulp-awspublish/releases
  - 4.x.x - Drop support for Node < 6
  - 5.x.x - Remove support for Node 10
  - 6.x.x -
    - _buildDeleteMultiple() requires passing bucket as argument
    - _toAwsParams() requires passing bucket as argument
    - Credentials passed to create() must be nested under credentials
- gulp-rename - https://github.com/hparra/gulp-rename/releases
  - Add the ability to use the function argument as an immutable map function
npm itself lets people know when they have outdated dependencies, let's
not ship extra dependencies if we don't need to :)
Bumps [semantic-release](https://github.com/semantic-release/semantic-release) from 19.0.2 to 19.0.3.
- [Release notes](https://github.com/semantic-release/semantic-release/releases)
- [Commits](semantic-release/semantic-release@v19.0.2...v19.0.3)

---
updated-dependencies:
- dependency-name: semantic-release
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <[email protected]>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- eslint - it still lints, so we good :D
- jest
  - 25: https://jestjs.io/blog/2020/01/21/jest-25
    - Drops Node.js 6
    - ESM exports
    - JSDOM upgrade from v11 to v15
  - 26: https://jestjs.io/blog/2020/05/05/jest-26
    - JSDOM v16
    - Drop Node.js 8
  - 27: https://jestjs.io/blog/2021/05/25/jest-27
    - Drops Node.js 13
    - Defaults to 'node' environment be default
  - 28: https://jestjs.io/blog/2022/04/25/jest-28
    - https://jestjs.io/docs/upgrading-to-jest28
    - Drops Node.js 10 and 15
- jsdoc-to-markdown: https://github.com/jsdoc2md/jsdoc-to-markdown/releases
  - 7.x.x: Dropped support for Node.js versions less than v14.
  - 6.x.x: Node versions less than v10 are no longer supported
  - 5.x.x: Node versions less than v8 are no longer supported
feat(smartcar): added support for simulated mode and feature flags
semantic-release's --branch flag got renamed to --branches
and it seems like we no longer need to do the mirror clone of the repo
These files already exist in S3 and therefore don't need to be re-built
and re-published everytime
@pull pull bot added the merge-conflict Resolve conflicts manually label Jul 28, 2022
allisonc07 and others added 2 commits September 25, 2025 15:21
* feat: make redirect_uri optional

* chore: update comment
* chore: move ci/cd

* feat: make redirect and scope optional
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

⤵️ pull merge-conflict Resolve conflicts manually

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants