Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump dprint from 0.35.1 to 0.41.0 #47

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Sep 11, 2023

Bumps dprint from 0.35.1 to 0.41.0.

Release notes

Sourced from dprint's releases.

0.41.0

Changes

  • feat: monitor and throttle CPU if necessary (#744)
  • fix: log and ignore PermissionDenied errors when globbing (#748)
  • fix: key Wasm cache on CPU features (#739) -- Fixes bug with caching on GH actions

Install

Run dprint upgrade or see https://dprint.dev/install/

Checksums

Artifact SHA-256 Checksum
dprint-x86_64-apple-darwin.zip 28ef80b29135b428c4b87d0b6468b9280f2dea97fd4bada27cf247c7b8870f2f
dprint-aarch64-apple-darwin.zip 3edb4521887bae5afe5ced25b5a540fc0f889b61cd335b3b4aab80b4d391981f
dprint-x86_64-pc-windows-msvc.zip f0416f1418d512066178c123daa5bf3dc061bcebd3e344906087762e3e6bc250
dprint-x86_64-pc-windows-msvc-installer.exe 95136710f7a3579e8ee45ee54dd067dfd702da26f6457b09819181904da9745a
dprint-x86_64-unknown-linux-gnu.zip 800621711bd455c5420bfa4e30e2482c3bc812e0af84e50de7d0c583ca9adb4e
dprint-x86_64-unknown-linux-musl.zip a22a0b771327e14bcb2508303502fa325bc85b2ca1c099ec49324c736be37fad
dprint-aarch64-unknown-linux-gnu.zip 736bae33b5ed619eafbb5f6bdf65f5806f728a7b51e229ba6732afd3117b8f89

0.40.2

Changes

  • fix: improve error message when process plugin is too old (#732)
  • fix: dprint init should not have includes pattern anymore (#730)

Install

Run dprint upgrade or see https://dprint.dev/install/

Checksums

Artifact SHA-256 Checksum
dprint-x86_64-apple-darwin.zip e4089c699a09ac725337f2f00f1de2798fa93e2cd7c739c81fdd85c3259b61e5
dprint-aarch64-apple-darwin.zip d1e7517270c7a04f38ff6659d0a20482c5406e66b2ae8e9c15abd4674e74c127
dprint-x86_64-pc-windows-msvc.zip ede70ca91ae7983f8365aa59c477246f9595c9f32536c359abf3a706c68801c8
dprint-x86_64-pc-windows-msvc-installer.exe 7ab88a5eee083835a710a0d364ec49c77a376587f6ae2b28d01d6ac240f95947
dprint-x86_64-unknown-linux-gnu.zip 32381717a408230405c15f185063ab953300d8eeb6814a2a3514a96358a84f5a
dprint-x86_64-unknown-linux-musl.zip 5c8418466937191f711ce4ba59e9ec28036daec01a08a505a17570a5edaec4c3
dprint-aarch64-unknown-linux-gnu.zip 66e51be4b1882f504beca45067fee39226b81c23c7fed0b71de629cafa51b7da

0.40.1

Changes

  • fix: do not error for --config in sub dir in some cases (regression in 0.40.0) (dprint/dprint#727)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [dprint](https://github.com/dprint/dprint) from 0.35.1 to 0.41.0.
- [Release notes](https://github.com/dprint/dprint/releases)
- [Commits](dprint/dprint@0.35.1...0.41.0)

---
updated-dependencies:
- dependency-name: dprint
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Sep 11, 2023

Dependabot tried to add @lowlighter as a reviewer to this PR, but received the following error from GitHub:

POST https://api.github.com/repos/Jerk400/metricshub/pulls/47/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the Jerk400/metricshub repository. // See: https://docs.github.com/rest/pulls/review-requests#request-reviewers-for-a-pull-request

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Sep 11, 2023

The following labels could not be found: 📦 dependencies.

@stackblitz
Copy link

stackblitz bot commented Sep 11, 2023

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@socket-security
Copy link

Updated dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
dprint 0.35.1...0.41.0 None +6/-0 125 MB dsherret

@socket-security
Copy link

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Issue Package Version Note Source
Empty package @dprint/darwin-arm64 0.41.0
No v1 @dprint/darwin-arm64 0.41.0
Empty package @dprint/darwin-x64 0.41.0
No v1 @dprint/darwin-x64 0.41.0
Empty package @dprint/linux-arm64-glibc 0.41.0
No v1 @dprint/linux-arm64-glibc 0.41.0
Empty package @dprint/linux-x64-glibc 0.41.0
No v1 @dprint/linux-x64-glibc 0.41.0
Empty package @dprint/linux-x64-musl 0.41.0
No v1 @dprint/linux-x64-musl 0.41.0
Empty package @dprint/win32-x64 0.41.0
No v1 @dprint/win32-x64 0.41.0
Environment variable access dprint 0.41.0

Next steps

What is an empty package?

Package does not contain any code. It may be removed, is name squatting, or the result of a faulty package publish.

Remove dependencies that do not export any code or functionality and ensure the package version includes all of the files it is supposed to.

What is wrong with semver < v1?

Package is not semver >=1. This means it is not stable and does not support ^ ranges.

If the package sees any general use, it should begin releasing at version 1.0.0 or later to benefit from semver.

What is environment variable access?

Package accesses environment variables, which may be a sign of credential stuffing or data theft.

Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore [email protected] bar@* or ignore all packages with @SocketSecurity ignore-all

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
0 participants