Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency sinon-chai to v4 #531

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 26, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
sinon-chai ~3.7.0 -> ~4.0.0 age adoption passing confidence

Release Notes

chaijs/sinon-chai (sinon-chai)

v4.0.0

Compare Source

What's Changed

New Contributors

Full Changelog: chaijs/sinon-chai@3.7.0...4.0.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link
Contributor Author

renovate bot commented Jul 26, 2024

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json
npm error code ERESOLVE
npm error ERESOLVE unable to resolve dependency tree
npm error
npm error While resolving: [email protected]
npm error Found: [email protected]
npm error node_modules/chai
npm error   dev chai@"~4.4.0" from the root project
npm error
npm error Could not resolve dependency:
npm error peer chai@"^5.0.0" from [email protected]
npm error node_modules/sinon-chai
npm error   dev sinon-chai@"~4.0.0" from the root project
npm error
npm error Fix the upstream dependency conflict, or retry
npm error this command with --force or --legacy-peer-deps
npm error to accept an incorrect (and potentially broken) dependency resolution.
npm error
npm error
npm error For a full report see:
npm error /tmp/renovate/cache/others/npm/_logs/2024-08-08T13_44_20_166Z-eresolve-report.txt
npm error A complete log of this run can be found in: /tmp/renovate/cache/others/npm/_logs/2024-08-08T13_44_20_166Z-debug-0.log

@renovate renovate bot added the dependencies Upgrade of project dependencies label Jul 26, 2024
@juliebrunetto83 juliebrunetto83 self-assigned this Jul 29, 2024
@renovate renovate bot force-pushed the renovate/sinon-chai-4.x branch 2 times, most recently from c4960b6 to 35f9118 Compare July 30, 2024 07:40
Copy link

socket-security bot commented Jul 30, 2024

🚨 Potential security issues detected. Learn more about Socket for GitHub ↗︎

To accept the risk, merge this PR and you will not be notified again.

Alert Package NoteSourceCI
Install scripts npm/@nestjs/[email protected]
  • Install script: postinstall
  • Source: opencollective || exit 0
🚫

View full report↗︎

Next steps

What is an install script?

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/[email protected] or ignore all packages with @SocketSecurity ignore-all

@renovate renovate bot force-pushed the renovate/sinon-chai-4.x branch 2 times, most recently from d47950f to 5186578 Compare August 1, 2024 07:39
@renovate renovate bot force-pushed the renovate/sinon-chai-4.x branch 3 times, most recently from ad154cc to 41eb2a9 Compare August 8, 2024 13:09
Copy link

socket-security bot commented Aug 8, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@nestjs/[email protected] Transitive: environment, eval, filesystem, network, shell, unsafe +243 59.8 MB nestjscore
npm/@nestjs/[email protected] None +4 600 kB nestjscore
npm/@nestjs/[email protected] environment, filesystem +2 1.48 MB nestjscore
npm/@nestjs/[email protected] environment, unsafe Transitive: filesystem, network, shell +18 1.5 MB nestjscore
npm/@nestjs/[email protected] network Transitive: environment, eval, filesystem, unsafe +83 2.72 MB nestjscore
npm/@nestjs/[email protected] None +1 120 kB nestjscore
npm/@salesforce/[email protected] Transitive: eval +20 7.18 MB salesforce-releases
npm/@sefr/[email protected] None 0 6.95 kB sefr
npm/@stryker-mutator/[email protected] Transitive: environment, eval, filesystem, network, shell, unsafe +198 31.8 MB strykermutator-npa
npm/@stryker-mutator/[email protected] Transitive: filesystem +6 674 kB strykermutator-npa
npm/@stryker-mutator/[email protected] Transitive: filesystem +7 783 kB strykermutator-npa
npm/@types/[email protected] None 0 26.1 kB types
npm/@types/[email protected] None 0 82.2 kB types
npm/@types/[email protected] None 0 120 kB types
npm/@types/[email protected] None 0 1.72 kB types
npm/@types/[email protected] None 0 95.9 kB types
npm/@types/[email protected] None +1 2.04 MB types
npm/@types/[email protected] None 0 6.53 kB types
npm/@types/[email protected] None +1 93.8 kB types
npm/@types/[email protected] None 0 7.08 kB types
npm/@typescript-eslint/[email protected] Transitive: environment, filesystem +40 8.2 MB jameshenry
npm/@typescript-eslint/[email protected] Transitive: environment, filesystem +34 3.35 MB jameshenry
npm/[email protected] network Transitive: environment, filesystem +8 2.49 MB jasonsaayman
npm/[email protected] filesystem, network 0 136 kB patrickjuchli
npm/[email protected] None +2 51.3 kB chaijs
npm/[email protected] None +7 920 kB keithamus
npm/[email protected] filesystem 0 143 kB ryu1kn
npm/[email protected] environment, filesystem 0 79.1 kB motdotla
npm/[email protected] None 0 38.3 kB lydell
npm/[email protected] environment, filesystem Transitive: eval, shell, unsafe +96 10.7 MB eslintbot
npm/[email protected] None +1 189 kB amitgupta
npm/[email protected] None +1 624 kB hellomichibye
npm/[email protected] None 0 4.33 MB icambron
npm/[email protected] network +5 1.41 MB meili-bot
npm/[email protected] filesystem, network Transitive: environment, eval +49 14.1 MB minio
npm/[email protected] environment, eval, filesystem +71 5.15 MB joshuakgoldberg
npm/[email protected] None 0 16.9 kB jmcdo29
npm/[email protected] environment Transitive: filesystem, shell, unsafe +78 11.8 MB jmcdo29
npm/[email protected] environment, filesystem, network +3 253 kB nockbot
npm/[email protected] filesystem 0 53.7 kB antelle
npm/[email protected] environment, filesystem, unsafe Transitive: eval, shell +147 17 MB bcoe
npm/[email protected] environment, unsafe Transitive: filesystem, network, shell +24 8.2 MB andrewww
npm/[email protected] environment, unsafe Transitive: eval, filesystem +22 1.91 MB matteo.collina
npm/[email protected] None 0 241 kB rbuckton
npm/[email protected] None +1 4.59 MB blesh
npm/[email protected] None 0 16.8 kB simondel
npm/[email protected] Transitive: environment, eval +12 7.65 MB fatso83
npm/[email protected] filesystem +1 90.2 kB linusu
npm/[email protected] environment, filesystem, unsafe +16 2.11 MB blakeembrey
npm/[email protected] None +1 7.93 MB martincizek
npm/[email protected] None 0 21.9 MB typescript-bot

🚮 Removed packages: npm/@tsconfig/[email protected], npm/[email protected], npm/[email protected], npm/[email protected], npm/[email protected]

View full report↗︎

@renovate renovate bot force-pushed the renovate/sinon-chai-4.x branch from 41eb2a9 to 202dd86 Compare August 8, 2024 13:44
@juliebrunetto83
Copy link
Contributor

la nouvelle version de sinon-chai supporte uniquement la version 5 de chai or on ne peut pas passer à la v5 de chai tant que le projet n'est pas en ESM.

Copy link
Contributor Author

renovate bot commented Aug 9, 2024

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future 4.x releases. But if you manually upgrade to 4.x then Renovate will re-enable minor and patch updates automatically.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate bot deleted the renovate/sinon-chai-4.x branch August 9, 2024 07:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Upgrade of project dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant