[Snyk] Upgrade: , , , chalk, ora, p-map, strip-ansi - #314
Open
mikolajroszak wants to merge 13 commits into
Open
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-DEBIAN10-LIBGCRYPT20-1297893 - https://snyk.io/vuln/SNYK-DEBIAN10-OPENSSL-1075326 - https://snyk.io/vuln/SNYK-DEBIAN10-OPENSSL-1569403 - https://snyk.io/vuln/SNYK-DEBIAN10-OPENSSL-1569406 - https://snyk.io/vuln/SNYK-DEBIAN10-OPENSSL-567125
…boweskorpuki.com Digitalex Army. Killo. kraboweskorpuki.com Mikołaj Roszak Krabowe Skorupki www.kraboweskorpuki.com Przedwiośnie 79/12 73-110 Stargard Skype +48500487977 Mikołaj Roszak "Konto Otwarte na Ciebie" Numer rachunku NRB: PL 8516 0014 6218 2200 1520 1405 63 KOD BIC/SWIFT Banku: PPABPLPKXXX Krabowe Skorupki www.kraboweskorpuki.com Przedwiośnie 79/12 Stargard, Zachodniopomorskie 73-110 Open hours: 10:00 - 17:00 Get Directions Call +48500487977
…5c5712a9d8214 [Snyk] Security upgrade python from 2.7-slim to 3.6-slim
Dane konta Revolut IBAN: LT41 3250 0894 7676 6825 BIC: REVOLT21 Konto (tylko przelewy krajowe): 2029 1000 0600 0000 0003 1339 92 Odbiorca: Mikołaj Roszak Adres odbiorcy: Przedwiośnie, 79/12, 73-110, Stargard, PL
Dane konta Revolut IBAN: LT41 3250 0894 7676 6825 BIC: REVOLT21 Konto (tylko przelewy krajowe): 2029 1000 0600 0000 0003 1339 92 Odbiorca: Mikołaj Roszak Adres odbiorcy: Przedwiośnie, 79/12, 73-110, Stargard, PL
Dane konta Revolut IBAN: LT41 3250 0894 7676 6825 BIC: REVOLT21 Konto (tylko przelewy krajowe): 2029 1000 0600 0000 0003 1339 92 Odbiorca: Mikołaj Roszak Adres odbiorcy: Przedwiośnie, 79/12, 73-110, Stargard, PL
Snyk has created this PR to upgrade:
- @snyk/dep-graph from 1.31.0 to 2.9.0.
See this package in npm: https://www.npmjs.com/package/@snyk/dep-graph
- @snyk/fix-pipenv-pipfile from 0.5.4 to 0.7.1.
See this package in npm: https://www.npmjs.com/package/@snyk/fix-pipenv-pipfile
- @snyk/fix-poetry from 0.8.0 to 0.9.1.
See this package in npm: https://www.npmjs.com/package/@snyk/fix-poetry
- chalk from 4.1.1 to 5.3.0.
See this package in npm: https://www.npmjs.com/package/chalk
- ora from 5.4.0 to 8.1.0.
See this package in npm: https://www.npmjs.com/package/ora
- p-map from 4.0.0 to 7.0.2.
See this package in npm: https://www.npmjs.com/package/p-map
- strip-ansi from 6.0.0 to 7.1.0.
See this package in npm: https://www.npmjs.com/package/strip-ansi
See this project in Snyk:
https://app.snyk.io/org/mikolaj-roszak/project/59371298-7f20-44d4-9537-7a320a026bac?utm_source=github&utm_medium=referral&page=upgrade-pr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@snyk/dep-graph
⚠️ This is a major version upgrade, and may be a breaking change | 3 months ago
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
⚠️ This is a major version upgrade, and may be a breaking change | 21 days ago
⚠️ This is a major version upgrade, and may be a breaking change | 5 months ago
⚠️ This is a major version upgrade, and may be a breaking change | a year ago
from 1.31.0 to 2.9.0 | 16 versions ahead of your current version
on 2024-06-05
@snyk/fix-pipenv-pipfile
from 0.5.4 to 0.7.1 | 5 versions ahead of your current version | a year ago
on 2023-07-13
@snyk/fix-poetry
from 0.8.0 to 0.9.1 | 5 versions ahead of your current version | a year ago
on 2023-07-13
chalk
from 4.1.1 to 5.3.0 | 8 versions ahead of your current version
on 2023-06-29
ora
from 5.4.0 to 8.1.0 | 14 versions ahead of your current version
on 2024-08-25
p-map
from 4.0.0 to 7.0.2 | 10 versions ahead of your current version
on 2024-04-03
strip-ansi
from 6.0.0 to 7.1.0 | 4 versions ahead of your current version
on 2023-05-28
Release notes
Package name: @snyk/dep-graph
-
2.9.0 - 2024-06-05
- Update CODEOWNERS (a8827c2)
-
2.8.1 - 2024-01-09
- lock down packageurl-js version (b31ee12)
-
2.8.0 - 2023-10-16
- Introduce optional limit for countPathsToRoot (ee11833)
-
2.7.4 - 2023-08-31
- validate golang purl version (3f1638e)
-
2.7.3 - 2023-08-29
- validation logic of cocoapods purls (87159ad)
-
2.7.2 - 2023-08-29
- consider purl subpath when validating golang package (e2c5bb7)
-
2.7.1 - 2023-07-17
- allow for namespaces in Purl validation (625e03e)
-
2.7.0 - 2023-06-16
- debian purls are validated on package name only (7cae162)
-
2.6.1 - 2023-05-09
- Fix countPathsToRoot for cyclic graphs (4b15635)
-
2.6.0 - 2023-03-29
- add new functionality to create a graph from unchanged packages (a0d5ba7)
-
2.5.0 - 2022-11-30
-
2.4.0 - 2022-11-14
-
2.3.0 - 2022-06-08
-
2.2.0 - 2022-06-08
-
2.1.0 - 2022-03-30
-
2.0.0 - 2022-03-30
-
1.31.0 - 2022-03-30
from @snyk/dep-graph GitHub release notes2.9.0 (2024-06-05)
Features
2.8.1 (2024-01-09)
Bug Fixes
2.8.0 (2023-10-16)
Features
2.7.4 (2023-08-31)
Bug Fixes
2.7.3 (2023-08-29)
Bug Fixes
2.7.2 (2023-08-29)
Bug Fixes
2.7.1 (2023-07-17)
Bug Fixes
2.7.0 (2023-06-16)
Features
2.6.1 (2023-05-09)
Bug Fixes
2.6.0 (2023-03-29)
Features
Package name: @snyk/fix-pipenv-pipfile
-
0.7.1 - 2023-07-13
-
0.7.0 - 2023-07-13
-
0.6.0 - 2022-10-25
-
0.5.6 - 2022-09-30
-
0.5.5 - 2021-10-04
-
0.5.4 - 2021-06-21
from @snyk/fix-pipenv-pipfile GitHub release notes@ snyk/fix-pipenv-pipfile@0.7.1
@ snyk/fix-pipenv-pipfile@0.7.0
Package name: @snyk/fix-poetry
-
0.9.1 - 2023-07-13
-
0.9.0 - 2023-07-13
-
0.8.3 - 2022-09-30
-
0.8.2 - 2022-06-29
-
0.8.1 - 2021-10-04
-
0.8.0 - 2021-09-23
from @snyk/fix-poetry GitHub release notes@ snyk/fix-poetry@0.9.1
@ snyk/fix-poetry@0.9.0
Package name: chalk
-
5.3.0 - 2023-06-29
- Add
- Add support for Gitea Actions (#603) 29b8569
-
5.2.0 - 2022-12-08
- Improve Deno compatibility (#579) 7443e9f
- Detect true-color support for GitHub Actions (#579) 7443e9f
- Detect true-color support for Kitty terminal (#579) 7443e9f
- Fix test for Azure DevOps environment (#579) 7443e9f
-
5.1.2 - 2022-10-12
- Fix exported styles names (#569) a34bcf6
-
5.1.1 - 2022-10-12
- Improved the names of exports introduced in 5.1.0 (#567) 6e0df05
- We of course preserved the old names.
-
5.1.0 - 2022-10-05
- Expose style names (#566) d7d7571
-
5.0.1 - 2022-03-08
- Add
-
5.0.0 - 2021-11-26
- This package is now pure ESM. Please read this.
- If you use TypeScript, you need to use TypeScript 4.7 or later. Why.
- If you use a bundler, make sure it supports ESM and that you have correctly configured it for ESM.
- The Chalk issue tracker is not a support channel for your favorite build/bundler tool.
- It's totally fine to stay on Chalk v4. It's been stable for years.
- Require Node.js 12.20 fa16f4e
- Move some properties off the default export to individual named exports:
- Remove
- These were not commonly used and added a lot of bloat to Chalk. You can achieve the same by using the
- The tagged template literal support moved into a separate package:
-import chalk from 'chalk';
- Bundle dependencies 04fdbd6
- This means Chalk no longer has any dependencies 🎉
- The install size is less than half of v4.
- Add
- Preserve function prototype methods (#434) 0fba91b
-
4.1.2 - 2021-07-30
- Readme updates
-
4.1.1 - 2021-04-21
- Readme updates 89e9e3a
from chalk GitHub release notessideEffectsfield to package.json 5aafc0av5.2.0...v5.3.0
v5.1.2...v5.2.0
v5.1.1...v5.1.2
v5.1.0...v5.1.1
v5.0.1...v5.1.0
mainfield to package.json for backwards compatibility with some developer tools 85f7e96v5.0.0...v5.0.1
Breaking
chalk.Instance→Chalkchalk.supportsColor→supportsColorchalk.stderr→chalkStderrchalk.stderr.supportsColor→supportsColorStderr.keyword(),.hsl(),.hsv(),.hwb(), and.ansi()coloring methods (#433) 4cf2e40color-convertpackage.chalk-template(#524) c987c61+import chalkTemplate from 'chalk-template';
-chalk
2 + 3 = {bold ${2 + 3}};+chalkTemplate
2 + 3 = {bold ${2 + 3}};Improvements
overlinestyle (#433) 4cf2e40v4.1.0...v5.0.0
Package name: ora
-
8.1.0 - 2024-08-25
- Update dependencies fb0fced
-
8.0.1 - 2023-12-23
- Fix the process not exiting 89a1f31
-
8.0.0 - 2023-12-22
- Require Node.js 18 675590f
- Update dependencies 675590f
-
7.0.1 - 2023-08-01
- Fix missing dependency (#228) 1dc1ece
-
7.0.0 - 2023-07-28
- Require Node.js 16 0e96acd
-
6.3.1 - 2023-05-15
- Fix Node.js 12 compatibility 4b1c2be
-
6.3.0 - 2023-03-24
- Add
-
6.2.0 - 2023-03-19
- Add
-
6.1.2 - 2022-06-27
- Revert "Fix preserving stdin's pause state (#210)" f4e03ea
- Reason: #211
-
6.1.1 - 2022-06-26
- Fix preserving stdin's pause state (#210) 77ccc1e
-
6.1.0 - 2022-02-21
-
6.0.1 - 2021-09-13
-
6.0.0 - 2021-08-23
-
5.4.1 - 2021-06-08
-
5.4.0 - 2021-03-17
from ora GitHub release notesv8.0.1...v8.1.0
v8.0.0...v8.0.1
Breaking
Improvements
v7.0.1...v8.0.0
v7.0.0...v7.0.1
Breaking
v6.3.1...v7.0.0
v6.3.0...v6.3.1
suffixTextoption (#223) 2378eafv6.2.0...v6.3.0
spinnersexport to be able to access all available spinners (#222) f2ac111v6.1.2...v6.2.0
v6.1.1...v6.1.2
v6.1.0...v6.1.1
Package name: p-map
-
7.0.2 - 2024-04-03
- Add missing
-
7.0.1 - 2023-12-27
- Fix
-
7.0.0 - 2023-12-05
- Require Node.js 18 (#67) 136b08a
- Add
-
6.0.0 - 2023-04-22
- Require Node.js 16 (#65) df88787
- Switch from
- This only affects you if you use
- The native one is similar, but differs in error message: sindresorhus/aggregate-error#4 (comment)
-
5.5.0 - 2022-06-09
- Add
-
5.4.0 - 2022-05-17
- Support
-
5.3.0 - 2021-11-02
- Add support for multiple
-
5.2.0 - 2021-10-27
- Add support for
- Prevent some potential unhandled exceptions (#48) 11bc75d
-
5.1.0 - 2021-07-23
- Add the ability to skip an iteration (#39) c9c0882
- Do not run mapping after stop-on-error happened (#40) 4b5f9e7
-
5.0.0 - 2021-04-17
- Require Node.js 12 dcdbc7a
- This package is now pure ESM. Please read this.
-
4.0.0 - 2020-03-05
from p-map GitHub release notesindexparameter to mapper function inpMapIterable(#71) dc597e5v7.0.1...v7.0.2
pMapIterablenot accepting async values in an iterator (#69) 1076833v7.0.0...v7.0.1
Breaking
Improvements
pMapIterableexport (#63) 5c59528v6.0.0...v7.0.0
Breaking
aggregate-errorpackage to the nativeAggregateError{stopOnError: false}.v5.5.0...v6.0.0
pMapSkipas an acceptable return value inMappertype (#60) b58fc26v5.4.0...v5.5.0
AbortController(#58) 4875deev5.3.0...v5.4.0
pMapSkip's (#52) 94eb532v5.2.0...v5.3.0
AsyncIterableas input (#46) a24e909v5.1.0...v5.2.0
Improvements
Fixes
v5.0.0...v5.1.0
Breaking
AggregateErroris no longer iterable. It moved to an.errorsproperty.v4.0.0...v5.0.0
Package name: strip-ansi
-
7.1.0 - 2023-05-28
- Improve performance (#49) 840a5ea
-
7.0.1 - 2021-09-11
- Upgrade dependencies ed41f38
-
7.0.0 - 2021-04-16
- Require Node.js 12 7cda68d
- This package is now pure ESM. Please read this.
-
6.0.1 - 2021-09-23
- Backport: Upgrade
-
6.0.0 - 2019-11-09
- Require Node.js 8 976f459
- Only use a CommonJS export for the TypeScript definition
from strip-ansi GitHub release notesv7.0.1...v7.1.0
v7.0.0...v7.0.1
Breaking
v6.0.0...v7.0.0
ansi-regexdependency: https://github.com/chalk/ansi-regex/releases/tag/v5.0.1v6.0.0...v6.0.1
Breaking
Breaking for TypeScript users
You need to change
import stripAnsi from 'strip-ansi';toimport stripAnsi = require('strip-ansi');v5.2.0...v6.0.0
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: