Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jan 10, 2022

Bumps copy-props from 2.0.4 to 2.0.5.

Release notes

Sourced from copy-props's releases.

2.0.5

Fix

  • Avoids prototype pollution (#7)

Doc

  • Update license years.
  • Transfer ownership to Gulp Team (#6)

Build

  • Update dependencies: each-props (>=1.3.2), is-plain-object (>=5.0.0).

Test

  • Expand test versions to v11〜v14.
Changelog

Sourced from copy-props's changelog.

Changelog

3.0.1 (2021-10-31)

Bug Fixes

  • ci: Rename prettierignore typo & avoid formatting web (192badf)
  • Update dependencies (ba8a51c)

3.0.0 (2021-09-25)

⚠ BREAKING CHANGES

  • Normalize repository, dropping node <10.13 support (#8)

Miscellaneous Chores

  • Normalize repository, dropping node <10.13 support (#8) (85b1165)
Commits
  • 40b7974 2.0.5
  • 2c738f5 Fix: Avoids prototype pollution (#7)
  • 4cac863 Merge: Transfer ownership to Gulp Team (#6)
  • 54a791d Doc: Transfer ownership to Gulp Team
  • 196fc9e Merge: Update dependencies and expand ci test versions (#5)
  • e89907f Test: Update npm to v4 when nodejs is v5 because of npm install error.
  • e970322 Test: Run coveralls when nodejs >= 6 because of its supports
  • 063e534 Test: Add nodejs v11-v14 into ci test versions
  • 72270af Doc: Update license years
  • f60b928 Build: Update versions of dependencies
  • See full diff in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Jan 10, 2022
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch from a472d17 to ff42a21 Compare February 15, 2022 17:27
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch from ff42a21 to f69e74f Compare March 17, 2022 10:20
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from e7254c0 to 149e4f0 Compare March 30, 2022 11:02
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch from 149e4f0 to 3d09bf2 Compare March 31, 2022 15:42
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 3 times, most recently from 9502b8e to 2fbe619 Compare April 13, 2022 11:17
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from 389cae7 to 3e027c8 Compare June 14, 2022 11:39
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from 4aa8ec4 to 86deb0f Compare June 23, 2022 09:00
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from 6a4cddb to bf0d91f Compare September 7, 2022 09:35
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from a410f6e to ed3d609 Compare October 24, 2022 13:27
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from ac702c5 to 2635f29 Compare November 4, 2022 11:20
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from 9a65ecc to 596e3f3 Compare November 25, 2022 11:55
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from c867cbc to 63b9c5d Compare November 29, 2022 11:22
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch 2 times, most recently from 2f80ba8 to f87f4be Compare December 22, 2022 10:50
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch from f87f4be to 57be58d Compare January 9, 2023 09:55
Bumps [copy-props](https://github.com/gulpjs/copy-props) from 2.0.4 to 2.0.5.
- [Release notes](https://github.com/gulpjs/copy-props/releases)
- [Changelog](https://github.com/gulpjs/copy-props/blob/master/CHANGELOG.md)
- [Commits](gulpjs/copy-props@2.0.4...2.0.5)

---
updated-dependencies:
- dependency-name: copy-props
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/copy-props-2.0.5 branch from 57be58d to 312d67f Compare January 9, 2023 09:55
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Mar 3, 2023

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

1 similar comment
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Mar 10, 2023

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Mar 15, 2023

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

2 similar comments
@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Mar 17, 2023

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

@dependabot @github
Copy link
Author

dependabot bot commented on behalf of github Mar 30, 2023

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot rebase.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant