-
Notifications
You must be signed in to change notification settings - Fork 329
build(deps-dev): bump ua-parser-js from 0.7.24 to 1.0.2 in /ui #3879
Conversation
@dependabot rebase |
Seems like this package had a major security issue: faisalman/ua-parser-js#536 |
It seems in a pretty sad maintenance state. The changelog is meaningless. I can’t tell why they cut a 1.0.0 version. I wonder if we could just ditch this dependency? |
23f6c00
to
793419c
Compare
We only use it in one place: waypoint/ui/app/routes/onboarding/install/index.ts Lines 2 to 8 in 2491bd3
|
793419c
to
982732c
Compare
982732c
to
9b67f9e
Compare
Bumps [ua-parser-js](https://github.com/faisalman/ua-parser-js) from 0.7.24 to 1.0.2. - [Release notes](https://github.com/faisalman/ua-parser-js/releases) - [Commits](faisalman/ua-parser-js@0.7.24...1.0.2) --- updated-dependencies: - dependency-name: ua-parser-js dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
9b67f9e
to
464b08e
Compare
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps ua-parser-js from 0.7.24 to 1.0.2.
Commits
1bf1c73
Bump version 1.0.297f3368
Bump version 0.7.31b86860e
Merge pull request #546 from hansott/master157af1e
Merge pull request #547 from sunny-mwx/patch-1b4cfe1b
Merge pull request #535 from shimar/fix/534-oppo-reno5-a95fea1c
Merge pull request #543 from catboy1006/master30648ce
✨ Use AST to verify whether regexes are safe10c978e
Update ua-parser.jsfbd2c68
feat: require the use of===
and!==
29d5e43
Securing the 1.x version (issue #536)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)