Bump the npm_and_yarn group across 2 directories with 3 updates#1
Bump the npm_and_yarn group across 2 directories with 3 updates#1dependabot[bot] wants to merge 1 commit intomasterfrom
Conversation
Bumps the npm_and_yarn group with 3 updates in the / directory: [electron-updater](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/electron-updater), [tmp](https://github.com/raszi/node-tmp) and [secp256k1](https://github.com/cryptocoinjs/secp256k1-node). Bumps the npm_and_yarn group with 1 update in the /packages/apps-electron directory: [electron-updater](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/electron-updater). Updates `electron-updater` from 5.3.0 to 6.3.0 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/master/packages/electron-updater/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/electron-updater@6.3.0/packages/electron-updater) Updates `tmp` from 0.2.1 to 0.2.4 - [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md) - [Commits](raszi/node-tmp@v0.2.1...v0.2.4) Updates `secp256k1` from 3.8.0 to 3.8.1 - [Release notes](https://github.com/cryptocoinjs/secp256k1-node/releases) - [Commits](cryptocoinjs/secp256k1-node@v3.8.0...v3.8.1) Updates `electron-updater` from 5.3.0 to 6.6.2 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/master/packages/electron-updater/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/electron-updater@6.3.0/packages/electron-updater) --- updated-dependencies: - dependency-name: electron-updater dependency-version: 6.3.0 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: tmp dependency-version: 0.2.4 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: secp256k1 dependency-version: 3.8.1 dependency-type: direct:production dependency-group: npm_and_yarn - dependency-name: electron-updater dependency-version: 6.6.2 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps the npm_and_yarn group with 3 updates in the / directory: electron-updater, tmp and secp256k1.
Bumps the npm_and_yarn group with 1 update in the /packages/apps-electron directory: electron-updater.
Updates
electron-updaterfrom 5.3.0 to 6.3.0Release notes
Sourced from electron-updater's releases.
... (truncated)
Changelog
Sourced from electron-updater's changelog.
... (truncated)
Commits
bfe4eccchore(deploy): Release v25.0.0 (electron-updater@6.3.0) (#8337)1320c0echore(deploy): Release v25.0.0-alpha.13 (electron-updater@6.3.0-alpha.8) (alp...fa3275cchore(deps): update dependency typescript to v5.5.3 (#8323)35a0784fix(rpm-updater): stop uninstalling app before update (#8311)dd145d6chore(deploy): Release v25.0.0-alpha.12 (electron-updater@6.3.0-alpha.7) (alp...2b80b01chore(deploy): Release v25.0.0-alpha.11 (electron-updater@6.3.0-alpha.6) (alp...ac2e6a2fix: verify LiteralPath of update file during windows signature verification ...5e924c2chore(deploy): Release v25.0.0-alpha.10 (electron-updater@6.3.0-alpha.5) (alp...29f6504chore(deploy): Release v25.0.0-alpha.9 (alpha) (#8241)48c5953fix(docs): update autoupdate docs noting thatchannelswork with Github (#8...Updates
tmpfrom 0.2.1 to 0.2.4Changelog
Sourced from tmp's changelog.
Commits
08fa3abUpdate version1cf4ec5Merge commit from fork188b25eFix GHSA-52f5-9888-hmc673b9fe4Add test case for GHSA-52f5-9888-hmc6b8e2f29Remove broken tests2892a02Remove outdated URLf592318Reformat package.json995ac8cMerge pull request #301 from raszi/dependabot/npm_and_yarn/braces-3.0.3caa758dBump braces from 3.0.2 to 3.0.35f0b252Merge pull request #297 from raszi/feat/release-v0.2.3Updates
secp256k1from 3.8.0 to 3.8.1Commits
69dcdf13.8.1e256905elliptic: fix key verification in loadCompressedPublicKey289dbc3Update elliptic to 6.5.7 (CVE-2024-42461) (#206)Updates
electron-updaterfrom 5.3.0 to 6.6.2Release notes
Sourced from electron-updater's releases.
... (truncated)
Changelog
Sourced from electron-updater's changelog.
... (truncated)
Commits
bfe4eccchore(deploy): Release v25.0.0 (electron-updater@6.3.0) (#8337)1320c0echore(deploy): Release v25.0.0-alpha.13 (electron-updater@6.3.0-alpha.8) (alp...fa3275cchore(deps): update dependency typescript to v5.5.3 (#8323)35a0784fix(rpm-updater): stop uninstalling app before update (#8311)dd145d6chore(deploy): Release v25.0.0-alpha.12 (electron-updater@6.3.0-alpha.7) (alp...2b80b01chore(deploy): Release v25.0.0-alpha.11 (electron-updater@6.3.0-alpha.6) (alp...ac2e6a2fix: verify LiteralPath of update file during windows signature verification ...5e924c2chore(deploy): Release v25.0.0-alpha.10 (electron-updater@6.3.0-alpha.5) (alp...29f6504chore(deploy): Release v25.0.0-alpha.9 (alpha) (#8241)48c5953fix(docs): update autoupdate docs noting thatchannelswork with Github (#8...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.