Skip to content
This repository was archived by the owner on Feb 29, 2024. It is now read-only.

Bump get-func-name and chai #33

Merged
merged 1 commit into from
Sep 28, 2023

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 27, 2023

Bumps get-func-name to 2.0.2 and updates ancestor dependency chai. These dependencies need to be updated together.

Updates get-func-name from 1.0.0 to 2.0.2

Release notes

Sourced from get-func-name's releases.

v2.0.2

What's Changed

Revert previous changes that shipped this as an ES module.

Full Changelog: https://github.com/chaijs/get-func-name/commits/v2.0.2

v2.0.1

What's Changed

Fix GHSA-4q6p-r6v2-jvc5

Full Changelog: https://github.com/chaijs/get-func-name/commits/v2.0.1

Commits
Maintainer changes

This version was pushed to npm by keithamus, a new releaser for get-func-name since your current version.


Updates chai from 4.0.0-canary.1 to 4.3.9

Release notes

Sourced from chai's releases.

v4.3.9

Upgrade dependencies.

This release upgrades dependencies to address CVE-2023-43646 where a large function name can cause "catastrophic backtracking" (aka ReDOS attack) which can cause the test suite to hang.

Full Changelog: chaijs/chai@v4.3.8...v4.3.9

v4.3.8

What's Changed

New Contributors

Full Changelog: chaijs/chai@v4.3.7...v4.3.8

v4.3.7

What's Changed

Full Changelog: chaijs/chai@v4.3.6...v4.3.7

v4.3.6

Update loupe to 2.3.1

v4.3.5

  • build chaijs fca5bb1
  • build(deps-dev): bump codecov from 3.1.0 to 3.7.1 (#1446) 747eb4e
  • fix package.json exports 022c2fa
  • fix: package.json - deprecation warning on exports field (#1400) 5276af6
  • feat: use chaijs/loupe for inspection (#1401) (#1407) c8a4e00

chaijs/chai@v4.3.4...v4.3.5

v4.3.4

This fixes broken inspect behavior with bigints (#1321) (#1383) thanks @​vapier

4.3.3 / 2021-03-03

This reintroduces Assertion as an export in the mjs file. See chaijs/chai#1378 & chaijs/chai#1375

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by keithamus, a new releaser for chai since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [get-func-name](https://github.com/chaijs/get-func-name) to 2.0.2 and updates ancestor dependency [chai](https://github.com/chaijs/chai). These dependencies need to be updated together.


Updates `get-func-name` from 1.0.0 to 2.0.2
- [Release notes](https://github.com/chaijs/get-func-name/releases)
- [Commits](https://github.com/chaijs/get-func-name/commits/v2.0.2)

Updates `chai` from 4.0.0-canary.1 to 4.3.9
- [Release notes](https://github.com/chaijs/chai/releases)
- [Changelog](https://github.com/chaijs/chai/blob/4.x.x/History.md)
- [Commits](chaijs/chai@4.0.0-canary.1...v4.3.9)

---
updated-dependencies:
- dependency-name: get-func-name
  dependency-type: indirect
- dependency-name: chai
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Sep 27, 2023
@kvz kvz merged commit 4dfac7e into master Sep 28, 2023
@kvz kvz deleted the dependabot/npm_and_yarn/get-func-name-and-chai-2.0.2 branch September 28, 2023 07:12
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant