Skip to content

Bump web-ext from 6.8.0 to 7.5.0#326

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web-ext-7.5.0
Closed

Bump web-ext from 6.8.0 to 7.5.0#326
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web-ext-7.5.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 25, 2023

Copy link
Copy Markdown
Contributor

Bumps web-ext from 6.8.0 to 7.5.0.

Release notes

Sourced from web-ext's releases.

7.5.0

Features

  • web-ext lint: updated to use addons-linter v5.27.0 (#2573, #2583, #2602, #2619)
    • import Firefox 109.0b9 API schema
    • ensure empty ZIP files will output results when auto-close feature is disabled
    • switch to vendored ajv-merge-patch library to fix a potential security issue
    • prevent errors when permissions in manifest.json isn't an array
  • web-ext sign: send user agent header with signing requests (#2540)

Bug Fixes

  • web-ext sign: added missing type for channel parameter (#2546)
  • web-ext sign: fixed the default AMO API base URL used by the experimental --use-submission-api CLI flag (#2621)
  • Other dependencies updated:
    • sign-addon to v5.2.0 (#2584)
    • camelcase to v7.0.1 (#2574)
    • eslint to v8.29.0 (#2569)
    • mocha to v10.2.0 (#2572)
    • prettier to v2.8.1 (#2571)
    • ... and some other dev dependencies

See all changes: mozilla/web-ext@7.4.0...7.5.0

7.4.0

Features

  • web-ext lint: enabled MV3 by default (#2557)
  • web-ext lint: updated to use addons-linter v5.23.0 (#2537) (#2561)
    • Firefox 108.0b5 schema has been imported
    • MV3 event pages are now fully supported by the linter
    • Various fixes related to CSP have been made in the linter

Bug Fixes

  • Other dependencies updated:

See all changes mozilla/web-ext@7.3.1...7.4.0

7.3.1

Bug Fixes

  • web-ext sign: fixed a bug that caused the experimental CLI flag --use-submission-api to use an invalid URL (#2531)

See all changes mozilla/web-ext@7.3.0...7.3.1

... (truncated)

Commits
  • fa989f7 7.5.0
  • 71e19d2 add trailing slash to amo-base-url & enforce within submit-addon Client (#2621)
  • 00250d0 chore(deps): bump @​babel/runtime from 7.20.7 to 7.20.13 (#2622)
  • 0bf4881 ci: use Node 18 in Circle CI (#2618)
  • ca817f3 chore: remove 'fast-json-patch' from the exclusion list in .nsprc (#2620)
  • 6659079 chore(deps): bump addons-linter from 5.26.0 to 5.27.0 (#2619)
  • 6356fa9 fix: Add missing type for channel parameter (#2546) (#2570)
  • 870b1d1 chore(deps-dev): bump eslint-plugin-import from 2.27.4 to 2.27.5 (#2613)
  • 9369afb chore(deps-dev): bump prettier from 2.8.2 to 2.8.3 (#2610)
  • 829884d chore(deps-dev): bump eslint from 8.31.0 to 8.32.0 (#2612)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [web-ext](https://github.com/mozilla/web-ext) from 6.8.0 to 7.5.0.
- [Release notes](https://github.com/mozilla/web-ext/releases)
- [Commits](mozilla/web-ext@6.8.0...7.5.0)

---
updated-dependencies:
- dependency-name: web-ext
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jan 25, 2023
@guardrails

guardrails Bot commented Jan 25, 2023

Copy link
Copy Markdown

⚠️ We detected 41 security issues in this pull request:

Vulnerable Libraries (41)
Severity Details
High @unimodules/react-native-adapter@6.1.0 (t) upgrade to: >6.1.0
High glob-watcher@5.0.5 (t) upgrade to: >=3.0.0
High gulp@4.0.2 (t) upgrade to: >=3.9.1
High ini@1.3.5 (t) upgrade to: >=1.3.6
High json5@1.0.1 (t) upgrade to: >=1.0.2
High minimatch@3.0.4 (t) upgrade to: >=3.0.5
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/react@18.2.0@18.2.0 (t) - no patch available
Medium pkg:npm/ws@6.2.2@6.2.2 (t) - no patch available
High pkg:npm/json5@1.0.1@1.0.1 (t) upgrade to: 2.2.2
Low pkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
Low pkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
N/A pkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
N/A pkg:npm/debug@2.6.9@2.6.9 (t) upgrade to: 3.1.0
N/A pkg:npm/decode-uri-component@0.2.0@0.2.0 (t) - no patch available
N/A pkg:npm/decode-uri-component@0.2.0@0.2.0 (t) - no patch available
Medium pkg:npm/eslint-plugin-no-unsanitized@4.0.2@4.0.2 (t) - no patch available
Medium pkg:npm/eslint-plugin-no-unsanitized@4.0.2@4.0.2 (t) - no patch available
High pkg:npm/ua-parser-js@0.7.33@0.7.33 (t) - no patch available
High pkg:npm/ua-parser-js@0.7.33@0.7.33 (t) - no patch available
High pkg:npm/moment@2.29.2@2.29.2 (t) upgrade to: 2.29.4,2.29.4
Critical pkg:npm/execa@1.0.0@1.0.0 (t) - no patch available
Critical pkg:npm/execa@1.0.0@1.0.0 (t) - no patch available
Critical pkg:npm/execa@1.0.0@1.0.0 (t) - no patch available
Medium pkg:npm/jszip@3.7.1@3.7.1 (t) - no patch available
Medium pkg:npm/jszip@3.7.1@3.7.1 (t) - no patch available
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
High pkg:npm/glob-parent@3.1.0@3.1.0 (t) upgrade to: 5.1.2
Critical pkg:npm/set-value@2.0.1@2.0.1 (t) - no patch available
Critical pkg:npm/set-value@2.0.1@2.0.1 (t) - no patch available
Medium pkg:npm/request@2.88.2@2.88.2 (t) - no patch available
High pkg:npm/yargs-parser@5.0.0-security.0@5.0.0-security.0 (t) - no patch available
Critical pkg:npm/msrcrypto@1.5.8@1.5.8 (t) - no patch available
High pkg:npm/flat@5.0.2@5.0.2 (t) - no patch available
High pkg:npm/flat@5.0.2@5.0.2 (t) - no patch available
Critical pkg:npm/unset-value@1.0.0@1.0.0 (t) - no patch available

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

@github-advanced-security

Copy link
Copy Markdown

You have successfully added a new CodeQL configuration .github/workflows/codeql-analysis.yml:analyze/language:javascript. As part of the setup process, we have scanned this repository and found no existing alerts. In the future, you will see all code scanning alerts on the repository Security tab.

@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2023

Copy link
Copy Markdown
Contributor Author

Superseded by #337.

@dependabot dependabot Bot closed this Jul 20, 2023
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/web-ext-7.5.0 branch July 20, 2023 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant