Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump the prod-deps group with 2 updates #938

Merged
merged 3 commits into from
Jan 8, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 8, 2024

Bumps the prod-deps group with 2 updates: @oclif/plugin-help and openid-client.

Updates @oclif/plugin-help from 6.0.9 to 6.0.10

Release notes

Sourced from @​oclif/plugin-help's releases.

6.0.10

Bug Fixes

  • deps: bump @​oclif/core from 3.15.1 to 3.16.0 (#615) (7cd7fc3)
Changelog

Sourced from @​oclif/plugin-help's changelog.

6.0.10 (2024-01-07)

Bug Fixes

  • deps: bump @​oclif/core from 3.15.1 to 3.16.0 (#615) (7cd7fc3)
Commits
  • d85f52b chore(release): 6.0.10 [skip ci]
  • 7cd7fc3 fix(deps): bump @​oclif/core from 3.15.1 to 3.16.0 (#615)
  • 417f3c3 chore(dev-deps): bump @​oclif/test from 3.1.7 to 3.1.8 (#616)
  • 23c1638 chore(dev-deps): bump eslint-config-oclif-typescript (#608)
  • 506a36b chore(dev-deps): bump @​types/node from 18.19.3 to 18.19.4 (#610)
  • 4abcf2a chore(dev-deps): bump @​oclif/test from 3.1.5 to 3.1.7 (#611)
  • e4fd2bc chore(dev-deps): bump eslint-config-oclif-typescript (#606)
  • f3f267c chore(dev-deps): bump @​oclif/test from 3.1.3 to 3.1.5 (#607)
  • fcd69fd chore(dev-deps): bump eslint from 8.55.0 to 8.56.0 (#601)
  • 312f5c1 chore(dev-deps): bump oclif from 4.0.4 to 4.1.0 (#602)
  • Additional commits viewable in compare view

Updates openid-client from 5.6.2 to 5.6.4

Release notes

Sourced from openid-client's releases.

v5.6.4

Revert "fix: encode client_secret_basic - _ . ! ~ * ' ( ) characters"

This reverts commit 5a2ea80ef5e59ec0c03dbd97d82f551e24a9d348, even though it is the correct implementation some of the most widely used identity providers don't follow the specification.

v5.6.3

Fixes

  • encode client_secret_basic - _ . ! ~ * ' ( ) characters (5a2ea80)
Changelog

Sourced from openid-client's changelog.

5.6.4 (2024-01-06)

5.6.3 (2024-01-05)

Fixes

  • encode client_secret_basic - _ . ! ~ * ' ( ) characters (5a2ea80)
Commits
  • 0e15612 chore(release): 5.6.4
  • 66c2ee2 Revert "fix: encode client_secret_basic - _ . ! ~ * ' ( ) characters"
  • 0378bba chore(release): 5.6.3
  • 5a2ea80 fix: encode client_secret_basic - _ . ! ~ * ' ( ) characters
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the prod-deps group with 2 updates: [@oclif/plugin-help](https://github.com/oclif/plugin-help) and [openid-client](https://github.com/panva/node-openid-client).


Updates `@oclif/plugin-help` from 6.0.9 to 6.0.10
- [Release notes](https://github.com/oclif/plugin-help/releases)
- [Changelog](https://github.com/oclif/plugin-help/blob/main/CHANGELOG.md)
- [Commits](oclif/plugin-help@6.0.9...6.0.10)

Updates `openid-client` from 5.6.2 to 5.6.4
- [Release notes](https://github.com/panva/node-openid-client/releases)
- [Changelog](https://github.com/panva/node-openid-client/blob/main/CHANGELOG.md)
- [Commits](panva/openid-client@v5.6.2...v5.6.4)

---
updated-dependencies:
- dependency-name: "@oclif/plugin-help"
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: openid-client
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team as a code owner January 8, 2024 13:58
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jan 8, 2024
Copy link

changeset-bot bot commented Jan 8, 2024

🦋 Changeset detected

Latest commit: a56e45d

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sigstore/cli Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@bdehamer bdehamer requested a review from ejahnGithub January 8, 2024 17:29
Copy link
Contributor

@ejahnGithub ejahnGithub left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@bdehamer bdehamer merged commit bfa5eeb into main Jan 8, 2024
26 checks passed
@bdehamer bdehamer deleted the dependabot/npm_and_yarn/prod-deps-147b89c56b branch January 8, 2024 18:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants