Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Dependabot suggested updates #340

Merged
merged 4 commits into from
Oct 24, 2023
Merged

chore: Dependabot suggested updates #340

merged 4 commits into from
Oct 24, 2023

Conversation

tuliomir
Copy link
Contributor

@tuliomir tuliomir commented Oct 4, 2023

Acceptance Criteria

  • All suggestions from DependaBot should be implemented
  • Default branch to be watched by DependaBot changed to dev

Implemented Dependabot suggestions

Changelog summaries of updated dependencies

activesupport:

  • Added protection for dangerous characters in names of tags and attributes
  • Avoids regex backtracking

cocoapods-downloader

concurrent-ruby

i18n

  • 1.11.0 bugfixes and improvements
  • 1.12.0 fix for a pluralization bug added

minitest

tzinfo

  • 2.0.5 improvements and security fixes
  • 2.0.6 fixes deprecation warnings

zeitwerk

  • 2.6.0 many improvements and six patches to fix or further improve the code up to 2.6.6

Security Checklist

  • Make sure you do not include new dependencies in the project unless strictly necessary and do not include dev-dependencies as production ones. More dependencies increase the possibility of one of them being hijacked and affecting us.

@tuliomir tuliomir added the dependencies Pull requests that update a dependency file label Oct 4, 2023
@tuliomir tuliomir self-assigned this Oct 4, 2023
@tuliomir tuliomir marked this pull request as draft October 4, 2023 19:29
@tuliomir tuliomir requested a review from r4mmer October 4, 2023 19:34
@tuliomir tuliomir changed the base branch from chore/nodejs-18 to dev October 20, 2023 15:46
@tuliomir tuliomir marked this pull request as ready for review October 20, 2023 15:46
@tuliomir tuliomir marked this pull request as draft October 24, 2023 11:29
@tuliomir tuliomir marked this pull request as ready for review October 24, 2023 11:29
This PR only forces an update on GitHub actions,
with no relevant change.
@tuliomir tuliomir merged commit f69c1e2 into dev Oct 24, 2023
@tuliomir tuliomir deleted the chore/dependabot branch October 24, 2023 11:44
@tuliomir tuliomir mentioned this pull request Oct 25, 2023
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
Archived in project
Development

Successfully merging this pull request may close these issues.

3 participants