Skip to content

Bump lockfile-lint from 4.6.2 to 4.10.1#243

Closed
dependabot[bot] wants to merge 1 commit into
socketlabs/mainfrom
dependabot/npm_and_yarn/lockfile-lint-4.10.1
Closed

Bump lockfile-lint from 4.6.2 to 4.10.1#243
dependabot[bot] wants to merge 1 commit into
socketlabs/mainfrom
dependabot/npm_and_yarn/lockfile-lint-4.10.1

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Feb 14, 2023

Bumps lockfile-lint from 4.6.2 to 4.10.1.

Changelog

Sourced from lockfile-lint's changelog.

4.10.1 (2023-02-13)

Note: Version bump only for package lockfile-lint

4.10.0 (2022-12-26)

Features

  • add support for yarn berry lockfiles (#147) (d4cf64d)

4.9.6 (2022-10-08)

Bug Fixes

  • cli parsing - handle correctly false value for validator (#146) (8f7e4c7)

4.9.5 (2022-09-30)

Bug Fixes

  • integrity: rename command-line argument from --validate-integrity-sha512 to --validate-integrity (#144) (a29d18b)

4.9.4 (2022-09-27)

Note: Version bump only for package lockfile-lint

4.9.3 (2022-09-26)

... (truncated)

Commits
  • 969ed05 chore(release): publish
  • 579bef2 docs: fix typo (#153)
  • 3ae9b8c chore(release): publish
  • 144dc55 chore(release): publish
  • 8f7e4c7 fix: cli parsing - handle correctly false value for validator (#146)
  • cb38c10 chore(release): publish
  • a29d18b fix(integrity): rename command-line argument from `--validate-integrity-sha51...
  • 6d689bd chore(release): publish
  • c4180ef chore(repository): defined repository.path property in package.json (#142)
  • aff1c57 chore(release): publish
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [lockfile-lint](https://github.com/lirantal/lockfile-lint/tree/HEAD/packages/lockfile-lint) from 4.6.2 to 4.10.1.
- [Release notes](https://github.com/lirantal/lockfile-lint/releases)
- [Changelog](https://github.com/lirantal/lockfile-lint/blob/master/packages/lockfile-lint/CHANGELOG.md)
- [Commits](https://github.com/lirantal/lockfile-lint/commits/lockfile-lint@4.10.1/packages/lockfile-lint)

---
updated-dependencies:
- dependency-name: lockfile-lint
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Feb 14, 2023
@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Feb 14, 2023

Dependabot tried to add @XhmikosR as a reviewer to this PR, but received the following error from GitHub:

POST https://api.github.com/repos/socketlabs/bootstrap/pulls/243/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the socketlabs/bootstrap repository. // See: https://docs.github.com/rest/reference/pulls#request-reviewers-for-a-pull-request

@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Feb 14, 2023

The following labels could not be found: v5.

@coveralls
Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 4173096421

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage increased (+0.03%) to 95.7%

Totals Coverage Status
Change from base Build 1916995879: 0.03%
Covered Lines: 1992
Relevant Lines: 2041

💛 - Coveralls

@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github May 30, 2023

Superseded by #267.

@dependabot dependabot Bot closed this May 30, 2023
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/lockfile-lint-4.10.1 branch May 30, 2023 10:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant