Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 22, 2020

Bumps node-notifier from 8.0.0 to 8.0.1.

Changelog

Sourced from node-notifier's changelog.

v8.0.1

  • fixes possible injection issue for notify-send
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.
@dependabot dependabot bot added automerge dd this label to any PRs that you want merged as soon as CI passes dependencies Pull requests that update a dependency file labels Dec 22, 2020
@codecov
Copy link

codecov bot commented Dec 22, 2020

Codecov Report

Merging #315 (7c157ca) into main (15d0077) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@ Coverage Diff @@ ## main #315 +/- ## ======================================= Coverage 93.12% 93.12% ======================================= Files 25 25 Lines 291 291 Branches 59 59 ======================================= Hits 271 271 Misses 19 19 Partials 1 1 

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 15d0077...7c157ca. Read the comment docs.

@dependabot dependabot bot force-pushed the dependabot-npm_and_yarn-node-notifier-8.0.1 branch from b76938e to e73b639 Compare January 20, 2021 01:49
@dependabot dependabot bot force-pushed the dependabot-npm_and_yarn-node-notifier-8.0.1 branch from e73b639 to 0106a2b Compare February 6, 2021 05:58
@github-actions github-actions bot force-pushed the dependabot-npm_and_yarn-node-notifier-8.0.1 branch 2 times, most recently from 33a81ba to dca29ae Compare February 8, 2021 19:17
@github-actions github-actions bot force-pushed the dependabot-npm_and_yarn-node-notifier-8.0.1 branch from dca29ae to 7c157ca Compare February 8, 2021 19:18
@github-actions github-actions bot merged commit 2f584da into main Feb 8, 2021
@github-actions github-actions bot deleted the dependabot-npm_and_yarn-node-notifier-8.0.1 branch February 8, 2021 19:22
@github-actions github-actions bot removed the automerge dd this label to any PRs that you want merged as soon as CI passes label Feb 8, 2021
@jrolfs
Copy link
Collaborator

jrolfs commented Feb 8, 2021

🎉 This PR is included in version 5.6.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@jrolfs jrolfs added the released label Feb 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file released

2 participants