-
Notifications
You must be signed in to change notification settings - Fork 3.2k
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Dependencies updated by Dependabot #156
Conversation
Bumps [npm-registry-fetch](https://github.com/npm/registry-fetch) from 3.8.0 to 3.9.0. - [Release notes](https://github.com/npm/registry-fetch/releases) - [Changelog](https://github.com/npm/npm-registry-fetch/blob/latest/CHANGELOG.md) - [Commits](npm/npm-registry-fetch@v3.8.0...v3.9.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [lodash](https://github.com/lodash/lodash) from 4.17.10 to 4.17.11. **This update includes security fixes.** - [Release notes](https://github.com/lodash/lodash/releases) - [Changelog](https://github.com/lodash/lodash/blob/master/CHANGELOG) - [Commits](lodash/lodash@4.17.10...4.17.11) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [tacks](https://github.com/iarna/tacks) from 1.2.7 to 1.3.0. - [Release notes](https://github.com/iarna/tacks/releases) - [Changelog](https://github.com/iarna/tacks/blob/master/CHANGES.md) - [Commits](iarna/tacks@v1.2.7...v1.3.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [npm-packlist](https://github.com/npm/npm-packlist) from 1.2.0 to 1.3.0. - [Release notes](https://github.com/npm/npm-packlist/releases) - [Commits](npm/npm-packlist@v1.2.0...v1.3.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [normalize-package-data](https://github.com/npm/normalize-package-data) from 2.4.0 to 2.5.0. - [Release notes](https://github.com/npm/normalize-package-data/releases) - [Commits](npm/normalize-package-data@v2.4.0...v2.5.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [lru-cache](https://github.com/isaacs/node-lru-cache) from 4.1.5 to 5.1.1. - [Release notes](https://github.com/isaacs/node-lru-cache/releases) - [Commits](isaacs/node-lru-cache@v4.1.5...v5.1.1) Signed-off-by: dependabot[bot] <support@dependabot.com>
…cache-5.1.1 Bump lru-cache from 4.1.5 to 5.1.1
…alize-package-data-2.5.0 Bump normalize-package-data from 2.4.0 to 2.5.0
…packlist-1.3.0 Bump npm-packlist from 1.2.0 to 1.3.0
…s-1.3.0 Bump tacks from 1.2.7 to 1.3.0
…sh-4.17.11 [Security] Bump lodash from 4.17.10 to 4.17.11
…registry-fetch-3.9.0 Bump npm-registry-fetch from 3.8.0 to 3.9.0
Bumps [tap](https://github.com/tapjs/node-tap) from 12.1.1 to 12.5.2. - [Release notes](https://github.com/tapjs/node-tap/releases) - [Changelog](https://github.com/tapjs/node-tap/blob/master/CHANGELOG.md) - [Commits](tapjs/tapjs@v12.1.1...v12.5.2) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [standard](https://github.com/standard/standard) from 11.0.1 to 12.0.1. - [Release notes](https://github.com/standard/standard/releases) - [Changelog](https://github.com/standard/standard/blob/master/CHANGELOG.md) - [Commits](standard/standard@v11.0.1...v12.0.1) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [sha](https://github.com/ForbesLindesay/sha) from 2.0.1 to 3.0.0. - [Release notes](https://github.com/ForbesLindesay/sha/releases) - [Commits](ForbesLindesay/sha@v2.0.1...v3.0.0) Signed-off-by: dependabot[bot] <support@dependabot.com>
Bumps [pacote](https://github.com/zkat/pacote) from 9.4.0 to 9.4.1. - [Release notes](https://github.com/zkat/pacote/releases) - [Changelog](https://github.com/zkat/pacote/blob/latest/CHANGELOG.md) - [Commits](zkat/pacote@v9.4.0...v9.4.1) Signed-off-by: dependabot[bot] <support@dependabot.com>
…ote-9.4.1 Bump pacote from 9.4.0 to 9.4.1
…3.0.0 Bump sha from 2.0.1 to 3.0.0
…dard-12.0.1 Bump standard from 11.0.1 to 12.0.1
…12.5.2 Bump tap from 12.1.1 to 12.5.2
This is 20 commits to update 4 dependencies; #155 was 12 to update 2. Is this what “dependabot” produces? |
Not usually. There's normally one commit from Dependabot creating the branch with a proposed update, then another when I merge the pull request into the default branch on my fork. |
See individual commits for details