Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump deep-object-diff from 1.1.7 to 1.1.9 #328

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 17, 2022

Bumps deep-object-diff from 1.1.7 to 1.1.9.

Release notes

Sourced from deep-object-diff's releases.

v1.1.9

Vulnerability patch

Details outlined here: #85. TLDR: The prototype of the returned diff object could be polluted but not globally on all objects.

Fix: mattphillips/deep-object-diff#87

Thanks @​Retr02332 for highlighting the issue and validating the fix.

This vulnerability was introduced in https://github.com/mattphillips/deep-object-diff/releases/tag/v1.1.6

v1.1.8

Patch

  • Fix typings resolution when using TypeScript 4.7+ with ESM #83
  • improve return type for detailedDiff #72

Credits

Thanks @​Nitive and @​icholy for your PRs

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Nov 17, 2022
@vercel
Copy link

vercel bot commented Nov 17, 2022

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated
react-components ✅ Ready (Inspect) Visit Preview 💬 Add your feedback Mar 9, 2023 at 8:46AM (UTC)
universal-header ✅ Ready (Inspect) Visit Preview 💬 Add your feedback Mar 9, 2023 at 8:46AM (UTC)

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from b238cc9 to 9d0fd5c Compare November 22, 2022 08:13
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 9d0fd5c to 23c6789 Compare November 25, 2022 03:37
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 23c6789 to fef9f90 Compare November 25, 2022 05:44
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from fef9f90 to 9011841 Compare November 28, 2022 09:45
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 9011841 to 260445a Compare November 29, 2022 07:02
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 260445a to 6610869 Compare November 30, 2022 06:23
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 6610869 to 566e29c Compare November 30, 2022 07:13
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 566e29c to c7765a7 Compare December 1, 2022 01:48
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from c7765a7 to 5918474 Compare December 1, 2022 03:12
@vercel
Copy link

vercel bot commented Dec 1, 2022

Deployment failed with the following error:

Resource is limited - try again in 3 hours (more than 100, code: "api-deployments-free-per-day").

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 9127df2 to 6ba29f1 Compare February 20, 2023 04:20
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 6ba29f1 to 52a777f Compare February 20, 2023 09:36
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 52a777f to 67b2b4c Compare February 22, 2023 09:48
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 67b2b4c to cea223c Compare February 23, 2023 04:42
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from cea223c to 1afc12d Compare February 23, 2023 09:01
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 1afc12d to 8e424d0 Compare March 7, 2023 05:21
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from 8e424d0 to f9e6a15 Compare March 7, 2023 07:02
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/deep-object-diff-1.1.9 branch from f9e6a15 to 32340cd Compare March 8, 2023 06:16
Bumps [deep-object-diff](https://github.com/mattphillips/deep-object-diff) from 1.1.7 to 1.1.9.
- [Release notes](https://github.com/mattphillips/deep-object-diff/releases)
- [Commits](https://github.com/mattphillips/deep-object-diff/commits)

---
updated-dependencies:
- dependency-name: deep-object-diff
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants