Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: Fix several vulnerabilities from dependabot #4711

Merged
merged 7 commits into from
Aug 29, 2023

Conversation

hlomzik
Copy link
Collaborator

@hlomzik hlomzik commented Aug 28, 2023

hlomzik and others added 3 commits August 28, 2023 23:07
Bumps [semver](https://github.com/npm/node-semver) from 5.7.1 to 5.7.2.
- [Release notes](https://github.com/npm/node-semver/releases)
- [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md)
- [Commits](npm/node-semver@v5.7.1...v5.7.2)

---
updated-dependencies:
- dependency-name: semver
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [word-wrap](https://github.com/jonschlinkert/word-wrap) from 1.2.3 to 1.2.4.
- [Release notes](https://github.com/jonschlinkert/word-wrap/releases)
- [Commits](jonschlinkert/word-wrap@1.2.3...1.2.4)

---
updated-dependencies:
- dependency-name: word-wrap
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@netlify
Copy link

netlify bot commented Aug 28, 2023

Deploy Preview for label-studio-docs-new-theme canceled.

Name Link
🔨 Latest commit 2496028
🔍 Latest deploy log https://app.netlify.com/sites/label-studio-docs-new-theme/deploys/64edc5f8c072ec0008f3c578

@netlify
Copy link

netlify bot commented Aug 28, 2023

Deploy Preview for heartex-docs canceled.

Name Link
🔨 Latest commit 2496028
🔍 Latest deploy log https://app.netlify.com/sites/heartex-docs/deploys/64edc5f816b85800080d4c26

@github-actions github-actions bot added the ci label Aug 28, 2023
@robot-ci-heartex
Copy link
Collaborator

To enable Auto Merge for this PR also merge those PRs:

@hlomzik hlomzik enabled auto-merge (squash) August 29, 2023 00:49
@hlomzik hlomzik merged commit c76a1a8 into develop Aug 29, 2023
30 checks passed
@hlomzik hlomzik deleted the fb-lsdv-5474/dependabot branch August 29, 2023 10:26
shayantabatabaee pushed a commit to shayantabatabaee/label-studio that referenced this pull request Sep 19, 2023
* ci: Fix hexo-utils back to fix dependabot issue

* chore(deps): bump semver from 5.7.1 to 5.7.2 in /label_studio/frontend

Bumps [semver](https://github.com/npm/node-semver) from 5.7.1 to 5.7.2.
- [Release notes](https://github.com/npm/node-semver/releases)
- [Changelog](https://github.com/npm/node-semver/blob/v5.7.2/CHANGELOG.md)
- [Commits](npm/node-semver@v5.7.1...v5.7.2)

---
updated-dependencies:
- dependency-name: semver
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump word-wrap in /label_studio/frontend

Bumps [word-wrap](https://github.com/jonschlinkert/word-wrap) from 1.2.3 to 1.2.4.
- [Release notes](https://github.com/jonschlinkert/word-wrap/releases)
- [Commits](jonschlinkert/word-wrap@1.2.3...1.2.4)

---
updated-dependencies:
- dependency-name: word-wrap
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

* [submodules] Build static HumanSignal/label-studio-frontend

Workflow run: https://github.com/HumanSignal/label-studio/actions/runs/6006494373

* [submodules] Build static HumanSignal/dm2

Workflow run: https://github.com/HumanSignal/label-studio/actions/runs/6006554741

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants