Size: a a a

2019 August 30

Dv

Dr. Friedrich von Ne... in chat-linker
А чо сразу я-то?
источник
2020 January 29

G

GitHub in chat-linker
🔨 2 new commits to chat-linker:master:

6206761: Bump lodash from 4.17.4 to 4.17.15

Bumps lodash from 4.17.4 to 4.17.15.
- Release notes
- Commits

Signed-off-by: dependabot[bot]  by dependabot[bot]
9c17579: Bump lodash from 4.17.4 to 4.17.15 (#71)

Bump lodash from 4.17.4 to 4.17.15 by Andrey Gurtovoy
источник

G

GitHub in chat-linker
🔨 1 new commit to chat-linker:dependabot/npm_and_yarn/stringstream-0.0.6:

0ec3f85: Bump stringstream from 0.0.5 to 0.0.6

Bumps stringstream from 0.0.5 to 0.0.6.
- Release notes
- Commits

Signed-off-by: dependabot[bot]  by dependabot[bot]
источник

G

GitHub in chat-linker
🔌 New pull request chat-linker#72 Bump stringstream from 0.0.5 to 0.0.6
by: @dependabot[bot]

Bumps stringstream from 0.0.5 to 0.0.6.
<details>
Commits</summary>

- `fee31c5` 0.0.6
- `2f4a9d4` Merge pull request #9 from mhart/fix-buffer-constructor-vuln
- `afbc744` Ensure data is not a number in Buffer constructor
- See full diff in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.`fee31c5` 0.0.6
- `2f4a9d4` Merge pull request #9 from mhart/fix-buffer-constructor-vuln
- `afbc744` Ensure data is not a number in Buffer constructor
- See full diff in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
источник

G

GitHub in chat-linker
🔨 1 new commit to chat-linker:dependabot/npm_and_yarn/js-yaml-3.13.1:

764db39: Bump js-yaml from 3.10.0 to 3.13.1

Bumps js-yaml from 3.10.0 to 3.13.1.
- Release notes
- Changelog
- Commits

Signed-off-by: dependabot[bot]  by dependabot[bot]
источник

G

GitHub in chat-linker
🔌 New pull request chat-linker#73 Bump js-yaml from 3.10.0 to 3.13.1
by: @dependabot[bot]

Bumps js-yaml from 3.10.0 to 3.13.1.
<details>
Changelog</summary>

Sourced from js-yaml's changelog.

> ## [3.13.1] - 2019-04-05
> ### Security
> - Fix possible code execution in (already unsafe) .load(), #480.
>
>
> ## [3.13.0] - 2019-03-20
> ### Security
> - Security fix: safeLoad() can hang when arrays with nested refs
>   used as key. Now throws exception for nested arrays. #475.
>
>
> ## [3.12.2] - 2019-02-26
> ### Fixed
> - Fix noArrayIndent option for root level, #468.
>
>
> ## [3.12.1] - 2019-01-05
> ### Added
> - Added noArrayIndent option, #432.
>
>
> ## [3.12.0] - 2018-06-02
> ### Changed
> - Support arrow functions without a block statement, #421.
>
>
> ## [3.11.0] - 2018-03-05
> ### Added
> - Add arrow functions suport for !!js/function.
>
> ### Fixed
> - Fix dump in bin/octal/hex formats for negative integers, #399.
</details>
<details>
Commits</summary>

- `665aadd` 3.13.1 released
- `da8ecf2` Browser files rebuild
- `b2f9e88` Merge pull request #480 from nodeca/toString
- `e18afbf` Fix possible code execution in (already unsafe) load()
- `9d4ce5e` 3.13.0 released
- `f64c673` Browser files rebuild
- `a567ef3` Restrict data types for object keys
- `59b6e76` Fix test name
- `e4267fc` 3.12.2 released
- `7231a49` Browser files rebuild
- Additional commits viewable in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.Sourced from js-yaml's changelog.js-yaml's changelog.

> ## [3.13.1] - 2019-04-05
> ### Security
> - Fix possible code execution in (already unsafe) .load(), #480.
>
>
> ## [3.13.0] - 2019-03-20
> ### Security
> - Security fix: safeLoad() can hang when arrays with nested refs
>   used as key. Now throws exception for nested arrays. #475.
>
>
> ## [3.12.2] - 2019-02-26
> ### Fixed
> - Fix noArrayIndent option for root level, #468.
>
>
> ## [3.12.1] - 2019-01-05
> ### Added
> - Added noArrayIndent option, #432.
>
>
> ## [3.12.0] - 2018-06-02
> ### Changed
> - Support arrow functions without a block statement, #421.
>
>
> ## [3.11.0] - 2018-03-05
> ### Added
> - Add arrow functions suport for !!js/function.
>
> ### Fixed
> - Fix dump in bin/octal/hex formats for negative integers, #399.
</details>
<details>
Commits</summary>

- `665aadd` 3.13.1 released
- `da8ecf2` Browser files rebuild
- `b2f9e88` Merge pull request #480 from nodeca/toString
- `e18afbf` Fix possible code execution in (already unsafe) load()
- `9d4ce5e` 3.13.0 released
- `f64c673` Browser files rebuild
- `a567ef3` Restrict data types for object keys
- `59b6e76` Fix test name
- `e4267fc` 3.12.2 released
- `7231a49` Browser files rebuild
- Additional commits viewable in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
источник

G

GitHub in chat-linker
🔨 1 new commit to chat-linker:dependabot/npm_and_yarn/fstream-1.0.12:

de659e5: Bump fstream from 1.0.11 to 1.0.12

Bumps fstream from 1.0.11 to 1.0.12.
- Release notes
- Commits

Signed-off-by: dependabot[bot]  by dependabot[bot]
источник

G

GitHub in chat-linker
🔨 1 new commit to chat-linker:dependabot/npm_and_yarn/tar-2.2.2:

66e8596: Bump tar from 2.2.1 to 2.2.2

Bumps tar from 2.2.1 to 2.2.2.
- Release notes
- Changelog
- Commits

Signed-off-by: dependabot[bot]  by dependabot[bot]
источник

G

GitHub in chat-linker
🔨 1 new commit to chat-linker:dependabot/npm_and_yarn/is-my-json-valid-2.20.0:

77392d7: Bump is-my-json-valid from 2.16.1 to 2.20.0

Bumps is-my-json-valid from 2.16.1 to 2.20.0.
- Release notes
- Commits

Signed-off-by: dependabot[bot]  by dependabot[bot]
источник

G

GitHub in chat-linker
🔌 New pull request chat-linker#74 Bump fstream from 1.0.11 to 1.0.12
by: @dependabot[bot]

Bumps fstream from 1.0.11 to 1.0.12.
<details>
Commits</summary>

- `4235459` 1.0.12
- `6a77d2f` Clobber a Link if it's in the way of a File
- See full diff in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.`4235459` 1.0.12
- `6a77d2f` Clobber a Link if it's in the way of a File
- See full diff in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
источник

G

GitHub in chat-linker
🔨 1 new commit to chat-linker:dependabot/npm_and_yarn/extend-3.0.2:

cb95473: Bump extend from 3.0.1 to 3.0.2

Bumps extend from 3.0.1 to 3.0.2.
- Release notes
- Changelog
- Commits

Signed-off-by: dependabot[bot]  by dependabot[bot]
источник

G

GitHub in chat-linker
🔌 New pull request chat-linker#75 Bump tar from 2.2.1 to 2.2.2
by: @dependabot[bot]

Bumps tar from 2.2.1 to 2.2.2.
<details>
Commits</summary>

- `523c5c7` 2.2.2
- `7ecef07` Bump fstream to fix hardlink overwriting vulnerability
- `9fc84b9` Use {} for hardlink tracking instead of []
- `15e59f1` Only track previously seen hardlinks
- `4f85851` Ignore potentially unsafe files
- See full diff in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.`523c5c7` 2.2.2
- `7ecef07` Bump fstream to fix hardlink overwriting vulnerability
- `9fc84b9` Use {} for hardlink tracking instead of []
- `15e59f1` Only track previously seen hardlinks
- `4f85851` Ignore potentially unsafe files
- See full diff in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
источник

G

GitHub in chat-linker
🔌 New pull request chat-linker#76 Bump is-my-json-valid from 2.16.1 to 2.20.0
by: @dependabot[bot]

Bumps is-my-json-valid from 2.16.1 to 2.20.0.
<details>
Commits</summary>

- `60111f4` 2.20.0
- `8c11f77` Merge pull request #175 from LinusU/meta
- `b6d9b3f` Cleanup package metadata
- `dcea5be` 2.19.0
- `1712811` Merge pull request #171 from mafintosh/ts-nullable
- `fad4c91` Add nullable types to TypeScript typings
- `484197f` Add test for nested object in typings
- `4bec868` Merge pull request #168 from mafintosh/ts-oneof
- `e8c30d5` Add support for "oneOf" to TypeScript typings
- `7160756` Merge pull request #167 from mafintosh/ts-required
- Additional commits viewable in compare view
</details>
<details>
Maintainer changes</summary>

This version was pushed to npm by linusu, a new releaser for is-my-json-valid since your current version.
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.`60111f4` 2.20.0
- `8c11f77` Merge pull request #175 from LinusU/meta
- `b6d9b3f` Cleanup package metadata
- `dcea5be` 2.19.0
- `1712811` Merge pull request #171 from mafintosh/ts-nullable
- `fad4c91` Add nullable types to TypeScript typings
- `484197f` Add test for nested object in typings
- `4bec868` Merge pull request #168 from mafintosh/ts-oneof
- `e8c30d5` Add support for "oneOf" to TypeScript typings
- `7160756` Merge pull request #167 from mafintosh/ts-required
- Additional commits viewable in compare view
</details>
<details>
Maintainer changes</summary>

This version was pushed to npm by linusu, a new releaser for is-my-json-valid since your current version.
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
источник

G

GitHub in chat-linker
🔌 New pull request chat-linker#77 Bump extend from 3.0.1 to 3.0.2
by: @dependabot[bot]

Bumps extend from 3.0.1 to 3.0.2.
<details>
Changelog</summary>

Sourced from extend's changelog.

> 3.0.2 / 2018-07-19
> ==================
>   * Fix] Prevent merging __proto__ property ([#48)
>   * [Dev Deps] update eslint, @ljharb/eslint-config, tape
>   * [Tests] up to node `v10.7`, v9.11, v8.11, v7.10, v6.14, v4.9`; use `nvm install-latest-npm
</details>
<details>
Commits</summary>

- `8d106d2` v3.0.2
- `e97091f` [Dev Deps] update tape
- `e841aac` [Tests] up to node `v10.7`
- `0e68e71` [Fix] Prevent merging __proto__ property
- `a689700` Only apps should have lockfiles
- `f13c1c4` [Dev Deps] update eslint, @ljharb/eslint-config, tape
- `f3570fe` [Tests] up to node `v10.0`, v9.11, v8.11, v7.10, v6.14, `v4.9`; use...
- See full diff in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.Sourced from extend's changelog.extend's changelog.

> 3.0.2 / 2018-07-19
> ==================
>   * Fix] Prevent merging __proto__ property ([#48)
>   * [Dev Deps] update eslint, @ljharb/eslint-config, tape
>   * [Tests] up to node `v10.7`, v9.11, v8.11, v7.10, v6.14, v4.9`; use `nvm install-latest-npm
</details>
<details>
Commits</summary>

- `8d106d2` v3.0.2
- `e97091f` [Dev Deps] update tape
- `e841aac` [Tests] up to node `v10.7`
- `0e68e71` [Fix] Prevent merging __proto__ property
- `a689700` Only apps should have lockfiles
- `f13c1c4` [Dev Deps] update eslint, @ljharb/eslint-config, tape
- `f3570fe` [Tests] up to node `v10.0`, v9.11, v8.11, v7.10, v6.14, `v4.9`; use...
- See full diff in compare view
</details>


![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
![Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
Dependabot commands and options</summary>


You can trigger Dependabot actions by commenting on this PR:
- @dependabot rebase will rebase this PR
- @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
- @dependabot merge will merge this PR after your CI passes on it
- @dependabot squash and merge will squash and merge this PR after your CI passes on it
- @dependabot cancel merge will cancel a previously requested merge and block automerging
- @dependabot reopen will reopen this PR if it is closed
- @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
- @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
- @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
- @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
- @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
- @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

</details>

Reply to this message to post a comment on GitHub.
источник

G

GitHub in chat-linker
🔨 1 new commit to chat-linker:dependabot/npm_and_yarn/sshpk-1.16.1:

38ea55d: Bump sshpk from 1.13.1 to 1.16.1

Bumps sshpk from 1.13.1 to 1.16.1.
- Release notes
- Commits

Signed-off-by: dependabot[bot]  by dependabot[bot]
источник
2020 January 30

G

GitHub in chat-linker
🐛 New issue chat-linker#79 demo doesn't seem to work
by @l29ah

https://github.com/jt3k/chat-linker/blob/master/README.md states that  

> demo XMPP-side: javascript@conference.jabber.ru (RU)

but it doesn't seem to be present there.

Reply to this message to post a comment on GitHub.
источник

G

GitHub in chat-linker
💬 New comment on chat-linker#79 demo doesn't seem to work
by @ForNeVeR

JavaScript is dead, sorry. One remaining instance is now serving in programming@cjr.

Reply to this message to post a comment on GitHub.
источник

G

GitHub in chat-linker
🔨 1 new commit to chat-linker:readme-fix:

822845c: Remove stopped demo by Friedrich von Never
источник

G

GitHub in chat-linker
🔌 New pull request chat-linker#80 Remove stopped demo
by: @ForNeVeR

I suggest we remove incorrect information from the README. We no longer provide the bot service in javascript@cjr.

Reply to this message to post a comment on GitHub.
источник
2020 January 31

G

GitHub in chat-linker
🔨 2 new commits to chat-linker:master:

822845c: Remove stopped demo by Friedrich von Never
e921735: Merge pull request #80 from jt3k/readme-fix

Remove stopped demo by Andrey Gurtovoy
источник