Apr
29
3 weeks ago
pull request

dependabot[bot] pull request gabrieltrompiz/electra-front

dependabot[bot]
dependabot[bot]

Bump async from 2.6.3 to 2.6.4

Bumps async from 2.6.3 to 2.6.4.

Changelog

Sourced from async's changelog.

v2.6.4

  • Fix potential prototype pollution exploit (#1828)
Commits
Maintainer changes

This version was pushed to npm by hargasinski, a new releaser for async since your current version.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Activity icon
created branch

dependabot[bot] in gabrieltrompiz/electra-front create branch dependabot/npm_and_yarn/async-2.6.4

createdAt 3 weeks ago
Apr
9
1 month ago
pull request

dependabot[bot] pull request gabrieltrompiz/electra-front

dependabot[bot]
dependabot[bot]

Bump moment from 2.24.0 to 2.29.2

Bumps moment from 2.24.0 to 2.29.2.

Changelog

Sourced from moment's changelog.

2.29.2 See full changelog

  • Release Apr 3 2022

Address https://github.com/advisories/GHSA-8hfj-j24r-96c4

2.29.1 See full changelog

  • Release Oct 6, 2020

Updated deprecation message, bugfix in hi locale

2.29.0 See full changelog

  • Release Sept 22, 2020

New locales (es-mx, bn-bd). Minor bugfixes and locale improvements. More tests. Moment is in maintenance mode. Read more at this link: https://momentjs.com/docs/#/-project-status/

2.28.0 See full changelog

  • Release Sept 13, 2020

Fix bug where .format() modifies original instance, and locale updates

2.27.0 See full changelog

  • Release June 18, 2020

Added Turkmen locale, other locale improvements, slight TypeScript fixes

2.26.0 See full changelog

  • Release May 19, 2020

TypeScript fixes and many locale improvements

2.25.3

  • Release May 4, 2020

Remove package.json module property. It looks like webpack behaves differently for modules loaded via module vs jsnext:main.

2.25.2

  • Release May 4, 2020

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Activity icon
created branch

dependabot[bot] in gabrieltrompiz/electra-front create branch dependabot/npm_and_yarn/moment-2.29.2

createdAt 1 month ago
Mar
25
1 month ago
Activity icon
delete

dependabot[bot] in gabrieltrompiz/electra-front delete branch dependabot/npm_and_yarn/electron-11.5.0

deleted time in 1 month ago
pull request

dependabot[bot] pull request gabrieltrompiz/electra-front

dependabot[bot]
dependabot[bot]

Bump electron from 7.1.7 to 11.5.0

Bumps electron from 7.1.7 to 11.5.0.

Release notes

Sourced from electron's releases.

electron v11.5.0

Release Notes for v11.5.0

Other Changes

  • Security: Backported fix for 1227933. #30614 (Also in 12)
  • Security: Backported fix for 1231134. #30761
  • Security: Backported fix for 1233564. #30755
  • Security: Backported fix for 1234009. #30751
  • Security: Backported fix for 1234764. #30659 (Also in 12)

End of Support for 11.x.y

Electron 11.x.y has reached end-of-support as per the project's support policy. Developers and applications are encouraged to upgrade to a newer version of Electron.

electron v11.4.12

Release Notes for v11.4.12

Fixes

electron v11.4.11

Release Notes for v11.4.11

Other Changes

  • Security: backported fix for 1205059,1196302. #30267
  • Security: backported fix for CVE-2021-30541. #30200
  • Security: backported fix for CVE-2021-30560. #30183
  • Security: backported fix for CVE-2021-30562. #30196
  • Security: backported fix for CVE-2021-30563. #30199
  • Security: backported fix for CVE-2021-30568. #30228
  • Security: backported fix for CVE-2021-30569. #30296
  • Security: backported fix for CVE-2021-30572. #30262
  • Security: backported fix for CVE-2021-30573. #30253

electron v11.4.10

Release Notes for v11.4.10

Other Changes

  • Backported fix for chromium:1211215. #29785
  • Security: backported fix for CVE-2021-30522. #29879
  • Security: backported fix for CVE-2021-30523. #29877
  • Security: backported fix for CVE-2021-30547. #29790
  • Security: backported fix for CVE-2021-30553. #29819
  • Security: backported fix for CVE-2021-30554. #29823
  • Security: backported fix for chromium:1194689. #29817
  • Security: backported fix for chromium:1209558. #29815

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Activity icon
issue

dependabot[bot] issue comment gabrieltrompiz/electra-front

dependabot[bot]
dependabot[bot]

Bump electron from 7.1.7 to 11.5.0

Bumps electron from 7.1.7 to 11.5.0.

Release notes

Sourced from electron's releases.

electron v11.5.0

Release Notes for v11.5.0

Other Changes

  • Security: Backported fix for 1227933. #30614 (Also in 12)
  • Security: Backported fix for 1231134. #30761
  • Security: Backported fix for 1233564. #30755
  • Security: Backported fix for 1234009. #30751
  • Security: Backported fix for 1234764. #30659 (Also in 12)

End of Support for 11.x.y

Electron 11.x.y has reached end-of-support as per the project's support policy. Developers and applications are encouraged to upgrade to a newer version of Electron.

electron v11.4.12

Release Notes for v11.4.12

Fixes

electron v11.4.11

Release Notes for v11.4.11

Other Changes

  • Security: backported fix for 1205059,1196302. #30267
  • Security: backported fix for CVE-2021-30541. #30200
  • Security: backported fix for CVE-2021-30560. #30183
  • Security: backported fix for CVE-2021-30562. #30196
  • Security: backported fix for CVE-2021-30563. #30199
  • Security: backported fix for CVE-2021-30568. #30228
  • Security: backported fix for CVE-2021-30569. #30296
  • Security: backported fix for CVE-2021-30572. #30262
  • Security: backported fix for CVE-2021-30573. #30253

electron v11.4.10

Release Notes for v11.4.10

Other Changes

  • Backported fix for chromium:1211215. #29785
  • Security: backported fix for CVE-2021-30522. #29879
  • Security: backported fix for CVE-2021-30523. #29877
  • Security: backported fix for CVE-2021-30547. #29790
  • Security: backported fix for CVE-2021-30553. #29819
  • Security: backported fix for CVE-2021-30554. #29823
  • Security: backported fix for chromium:1194689. #29817
  • Security: backported fix for chromium:1209558. #29815

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

pull request

dependabot[bot] pull request gabrieltrompiz/electra-front

dependabot[bot]
dependabot[bot]

Bump electron from 7.1.7 to 13.6.6

Bumps electron from 7.1.7 to 13.6.6.

Release notes

Sourced from electron's releases.

electron v13.6.6

Release Notes for v13.6.6

Fixes

  • Fixed a JavaScript exception from webContents if render frame was disposed in WebFrameMain, resets the value of render_frame_disposed_ after updating render frame host. #32130 (Also in 14, 15, 16)
  • No Notes. #32241 (Also in 14, 15, 16, 17)

Other Changes

  • Backported fix for CVE-2021-4056. #32237
  • Backported fix for CVE-2021-4057. #32234
  • Backported fix for CVE-2021-4102. #32194

electron v13.6.3

Release Notes for v13.6.3

Fixes

  • Fixed window frame glitch when calling setContentProtection. #31829 (Also in 14, 15, 16)
  • Generate valid config.gypi file in Node.js headers. #31989 (Also in 14, 15, 16)

Other Changes

  • Backported fix for CVE-2021-38005. #31921
  • Backported fix for CVE-2021-38007. #31912
  • Backported fix for CVE-2021-38011. #31901

electron v13.6.2

Release Notes for v13.6.2

Fixes

  • Fixed an issue where Content-Disposition filenames would be incorrectly truncated at the first comma for a filename attachment which contained one. #31691 (Also in 14, 15, 16)
  • Fixed an issue which caused print settings to not work properly when printing silently. #31618 (Also in 14, 15, 16)

Other Changes

  • Backported fix for CVE-2021-37998. #31678
  • Backported fix for CVE-2021-38001. #31673
  • Backported fix for CVE-2021-38002. #31671
  • Backported fix for CVE-2021-38003. #31665
  • Backported fix for chromium:1252858. #31682

electron v13.6.1

Release Notes for v13.6.1

Fixes

  • Fixed an issue where MediaMetadata did not work properly. #31532 (Also in 14, 15, 16)
  • Fixed black window when screen capturing a content-protected BrowserWindow on Windows 10. #31550 (Also in 14, 15, 16)

Other Changes

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Activity icon
created branch

dependabot[bot] in gabrieltrompiz/electra-front create branch dependabot/npm_and_yarn/electron-13.6.6

createdAt 1 month ago
Feb
26
2 months ago
Activity icon
delete

dependabot[bot] in gabrieltrompiz/electra-front delete branch dependabot/npm_and_yarn/url-parse-1.5.7

deleted time in 2 months ago
Previous