Created by: dependabot[bot]
Bumps semantic-release from 17.4.2 to 19.0.3.
Release notes
Sourced from semantic-release's releases.
v19.0.3
19.0.3 (2022-06-09)
Bug Fixes
- log-repo: use the original form of the repo url to remove the need to mask credentials (#2459) (58a226f), closes #2449
v19.0.2
19.0.2 (2022-01-18)
Bug Fixes
- npm-plugin: upgraded to the stable version (0eca144)
v19.0.1
19.0.1 (2022-01-18)
Bug Fixes
- npm-plugin: upgraded to the latest beta version (8097afb)
v19.0.0
19.0.0 (2022-01-18)
Bug Fixes
- npm-plugin: upgraded to the beta, which upgrades npm to v8 (f634b8c)
- upgrade
marked
to resolve ReDos vulnerability (#2330) (d9e5bc0)BREAKING CHANGES
- npm-plugin:
@semantic-release/npm
has also dropped support for node v15- node v15 has been removed from our defined supported versions of node. this was done to upgrade to compatible versions of
marked
andmarked-terminal
that resolved the ReDoS vulnerability. removal of support of this node version should be low since it was not an LTS version and has been EOL for several months already.v19.0.0-beta.2
19.0.0-beta.2 (2022-01-17)
Bug Fixes
- npm-plugin: upgraded to the beta, which upgrades npm to v8 (f634b8c)
... (truncated)
Commits
-
58a226f
fix(log-repo): use the original form of the repo url to remove the need to ma... -
17d60d3
build(deps): bump npm from 8.3.1 to 8.12.0 (#2447) -
ab45ab1
chore(lint): disabled rules that dont apply to this project (#2408) -
ea389c3
chore(deps): update dependency yargs-parser to 13.1.2 [security] (#2402) -
fa994db
build(deps): bump node-fetch from 2.6.1 to 2.6.7 (#2399) -
b79116b
build(deps): bump trim-off-newlines from 1.0.1 to 1.0.3 -
6fd7e56
build(deps): bump minimist from 1.2.5 to 1.2.6 -
2b94bb4
docs: update broken link to CI config recipes (#2378) -
b4bc191
docs: Correct circleci workflow (#2365) -
2c30e26
Merge pull request #2333 from semantic-release/next - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.