chore(depends): bump minimatch, electron-builder and @electron/universal in /Mod Manager#553
Conversation
Bumps [minimatch](https://github.com/isaacs/minimatch) to 3.1.2 and updates ancestor dependencies [minimatch](https://github.com/isaacs/minimatch), [electron-builder](https://github.com/electron-userland/electron-builder/tree/HEAD/packages/electron-builder) and [@electron/universal](https://github.com/electron/universal). These dependencies need to be updated together. Updates `minimatch` from 3.0.4 to 3.1.2 - [Release notes](https://github.com/isaacs/minimatch/releases) - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v3.0.4...v3.1.2) Updates `electron-builder` from 23.3.3 to 24.0.0 - [Release notes](https://github.com/electron-userland/electron-builder/releases) - [Changelog](https://github.com/electron-userland/electron-builder/blob/master/packages/electron-builder/CHANGELOG.md) - [Commits](https://github.com/electron-userland/electron-builder/commits/v24.0.0/packages/electron-builder) Updates `@electron/universal` from 1.2.1 to 1.3.4 - [Release notes](https://github.com/electron/universal/releases) - [Changelog](https://github.com/electron/universal/blob/main/.releaserc.json) - [Commits](electron/universal@v1.2.1...v1.3.4) --- updated-dependencies: - dependency-name: minimatch dependency-type: indirect - dependency-name: electron-builder dependency-type: direct:development - dependency-name: "@electron/universal" dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Socket Security Pull Request ReportDependency issues detected: If you merge this pull request, you will not be alerted to the instances of these issues again. 🫣 Native codeContains native code which could be a vector to obscure malicious code, and generally decrease the likelihood of reproducible or reliable installs. Ensure that native code bindings are expected. Consumers may consider pure JS and functionally similar alternatives to avoid the challenges and risks associated with native code bindings.
Pull request report summary
Bot CommandsTo ignore an alert, reply with a comment starting with
Powered by socket.dev |
|
Download the artifacts for this pull request: |
Bumps minimatch to 3.1.2 and updates ancestor dependencies minimatch, electron-builder and @electron/universal. These dependencies need to be updated together.
Updates
minimatchfrom 3.0.4 to 3.1.2Commits
699c4593.1.22f2b5fffix: trim pattern25d7c0d3.1.155dda29fix: treat nocase:true as always having magic5e1fb8d3.1.0f8145c5Add 'allowWindowsEscape' option570e8b1add publishConfig for v3 publishes5b7cd333.0.620b4b56[fix] revert all breaking syntax changes2ff0388document, expose, and test 'partial:true' optionUpdates
electron-builderfrom 23.3.3 to 24.0.0Release notes
Sourced from electron-builder's releases.
... (truncated)
Changelog
Sourced from electron-builder's changelog.
... (truncated)
Commits
c1448c6chore(deploy): Release 24.0.0 (electron-updater@6.0.0) (#7459)c6ea568chore(deploy): Release 24.0.0-alpha.13 (alpha) (#7433)8ba58fachore(deploy): Release 24.0.0-alpha.12 (electron-updater@6.0.0-alpha.9) (alph...a338730feat: Allow for NSIS windows installer to be wrapped in an MSI (#7407)0448896chore(deploy): Release 24.0.0-alpha.11 (electron-updater@6.0.0-alpha.8) (alph...45d2921chore(deploy): Release 24.0.0-alpha.10 (alpha) (#7363)1bd574bchore(deploy): Release 24.0.0-alpha.9 (electron-updater@6.0.0-alpha.7) (alpha...9b265f4chore(deploy): Release 24.0.0-alpha.8 (electron-updater@6.0.0-alpha.6) (alpha...a6d135dchore(deploy): Release 24.0.0-alpha.7 (alpha) (#7312)a117ccbchore(deploy): Release 24.0.0-alpha.6 (electron-updater@6.0.0-alpha.5) (alpha...Updates
@electron/universalfrom 1.2.1 to 1.3.4Release notes
Sourced from
@electron/universal's releases.Commits
3657753fix: update dir-compare for minimatch redos1fc0005fix: merged ASAR does not unpack when there is only one unpacked file (#55)64cbc83build: configure semantic release for main branch691e4effix: migrate from asar to@electron/asard902197build: migrate master <-> main72a3f83fix: export MakeUniversalOpts (#48)3cc1365Update config.yml3a30fe9build(deps): bump plist from 3.0.4 to 3.0.5 (#44)01dfb8afeat: don't lipo binaries that are identical in the x64 and arm64 versions an...3bd173dbuild(deps): bump minimist from 1.2.5 to 1.2.6You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.