[GitHub] [nifi-fds] dependabot[bot] opened a new pull request, #75: Bump ua-parser-js from 0.7.31 to 0.7.33

2023-01-27 Thread dependabot


dependabot[bot] opened a new pull request, #75:
URL: https://github.com/apache/nifi-fds/pull/75

   Bumps [ua-parser-js](https://github.com/faisalman/ua-parser-js) from 0.7.31 
to 0.7.33.
   
   Changelog
   Sourced from https://github.com/faisalman/ua-parser-js/blob/master/changelog.md";>ua-parser-js's
 changelog.
   
   Version 0.7.31 / 1.0.2
   
   Fix OPPO Reno A5 incorrect detection
   Fix TypeError Bug
   Use AST to extract regexes and verify them with safe-regex
   
   Version 0.7.32 / 1.0.32
   
   Add new browser : DuckDuckGo, Huawei Browser, LinkedIn
   Add new OS : HarmonyOS
   Add some Huawei models
   Add Sharp Aquos TV
   Improve detection Xiaomi Mi CC9
   Fix Sony Xperia 1 III misidentified as Acer tablet
   Fix Detect Sony BRAVIA as SmartTV
   Fix Detect Xiaomi Mi TV as SmartTV
   Fix Detect Galaxy Tab S8 as tablet
   Fix WeGame mistakenly identified as WeChat
   Fix included commas in Safari / Mobile Safari version
   Increase UA_MAX_LENGTH to 350
   
   Version 0.7.33 / 1.0.33
   
   Add new browser : Cobalt
   Identify Macintosh as an Apple device
   Fix ReDoS vulnerability
   
   Version 0.8
   Version 0.8 was created by accident. This version is now deprecated and 
no longer maintained, please update to version 0.7 / 1.0.
   
   
   
   Commits
   
   https://github.com/faisalman/ua-parser-js/commit/f2d0db001d87da15de7b9b1df7be9f2eacefd8c5";>f2d0db0
 Bump version 0.7.33
   https://github.com/faisalman/ua-parser-js/commit/a6140a17dd0300a35cfc9cff999545f267889411";>a6140a1
 Remove unsafe regex in trim() function
   https://github.com/faisalman/ua-parser-js/commit/a88660493568d6144a551424a8139d6c876635f6";>a886604
 Fix https://github-redirect.dependabot.com/faisalman/ua-parser-js/issues/605";>#605
 - Identify Macintosh as Apple device
   https://github.com/faisalman/ua-parser-js/commit/b814bcd79198e730936c82462e2d729eb5423e3c";>b814bcd
 Merge pull request https://github-redirect.dependabot.com/faisalman/ua-parser-js/issues/606";>#606
 from rileyjshaw/patch-1
   https://github.com/faisalman/ua-parser-js/commit/7f71024161399b7aa5d5cd10dba9e059f0218262";>7f71024
 Fix documentation
   https://github.com/faisalman/ua-parser-js/commit/c239ac5167abd574a635cb809a2b4fa35810d23b";>c239ac5
 Merge pull request https://github-redirect.dependabot.com/faisalman/ua-parser-js/issues/604";>#604
 from obecerra3/master
   https://github.com/faisalman/ua-parser-js/commit/8d3c2d327cf540ff2c050f1cc67bca8c6f8e4458";>8d3c2d3
 Add new browser: Cobalt
   https://github.com/faisalman/ua-parser-js/commit/d11fc47dc9b6acc0f89fc10c120cea08e10cd31a";>d11fc47
 Bump version 0.7.32
   https://github.com/faisalman/ua-parser-js/commit/b490110109de586deab96c775c9ef0dfc9c919c4";>b490110
 Merge branch 'develop' of github.com:faisalman/ua-parser-js
   https://github.com/faisalman/ua-parser-js/commit/cb5da5ea4b220d5b60fe209e123b7f911d8e0d4a";>cb5da5e
 Merge pull request https://github-redirect.dependabot.com/faisalman/ua-parser-js/issues/600";>#600
 from moekm/develop
   Additional commits viewable in https://github.com/faisalman/ua-parser-js/compare/0.7.31...0.7.33";>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ua-parser-js&package-manager=npm_and_yarn&previous-version=0.7.31&new-version=0.7.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@depen

[GitHub] [nifi] dependabot[bot] opened a new pull request, #6896: Bump ua-parser-js and karma in /nifi-registry/nifi-registry-core/nifi-registry-web-ui/src/main

2023-01-26 Thread dependabot


dependabot[bot] opened a new pull request, #6896:
URL: https://github.com/apache/nifi/pull/6896

   Bumps [ua-parser-js](https://github.com/faisalman/ua-parser-js) to 0.7.33 
and updates ancestor dependency [karma](https://github.com/karma-runner/karma). 
These dependencies need to be updated together.
   
   Updates `ua-parser-js` from 0.7.22 to 0.7.33
   
   Changelog
   Sourced from https://github.com/faisalman/ua-parser-js/blob/master/changelog.md";>ua-parser-js's
 changelog.
   
   Version 0.7.33 / 1.0.33
   
   Add new browser : Cobalt
   Identify Macintosh as an Apple device
   Fix ReDoS vulnerability
   
   Version 0.8
   Version 0.8 was created by accident. This version is now deprecated and 
no longer maintained, please update to version 0.7 / 1.0.
   
   
   
   Commits
   
   https://github.com/faisalman/ua-parser-js/commit/f2d0db001d87da15de7b9b1df7be9f2eacefd8c5";>f2d0db0
 Bump version 0.7.33
   https://github.com/faisalman/ua-parser-js/commit/a6140a17dd0300a35cfc9cff999545f267889411";>a6140a1
 Remove unsafe regex in trim() function
   https://github.com/faisalman/ua-parser-js/commit/a88660493568d6144a551424a8139d6c876635f6";>a886604
 Fix https://github-redirect.dependabot.com/faisalman/ua-parser-js/issues/605";>#605
 - Identify Macintosh as Apple device
   https://github.com/faisalman/ua-parser-js/commit/b814bcd79198e730936c82462e2d729eb5423e3c";>b814bcd
 Merge pull request https://github-redirect.dependabot.com/faisalman/ua-parser-js/issues/606";>#606
 from rileyjshaw/patch-1
   https://github.com/faisalman/ua-parser-js/commit/7f71024161399b7aa5d5cd10dba9e059f0218262";>7f71024
 Fix documentation
   https://github.com/faisalman/ua-parser-js/commit/c239ac5167abd574a635cb809a2b4fa35810d23b";>c239ac5
 Merge pull request https://github-redirect.dependabot.com/faisalman/ua-parser-js/issues/604";>#604
 from obecerra3/master
   https://github.com/faisalman/ua-parser-js/commit/8d3c2d327cf540ff2c050f1cc67bca8c6f8e4458";>8d3c2d3
 Add new browser: Cobalt
   https://github.com/faisalman/ua-parser-js/commit/d11fc47dc9b6acc0f89fc10c120cea08e10cd31a";>d11fc47
 Bump version 0.7.32
   https://github.com/faisalman/ua-parser-js/commit/b490110109de586deab96c775c9ef0dfc9c919c4";>b490110
 Merge branch 'develop' of github.com:faisalman/ua-parser-js
   https://github.com/faisalman/ua-parser-js/commit/cb5da5ea4b220d5b60fe209e123b7f911d8e0d4a";>cb5da5e
 Merge pull request https://github-redirect.dependabot.com/faisalman/ua-parser-js/issues/600";>#600
 from moekm/develop
   Additional commits viewable in https://github.com/faisalman/ua-parser-js/compare/0.7.22...0.7.33";>compare
 view
   
   
   
   
   Updates `karma` from 5.2.3 to 6.4.1
   
   Release notes
   Sourced from https://github.com/karma-runner/karma/releases";>karma's 
releases.
   
   v6.4.1
   https://github.com/karma-runner/karma/compare/v6.4.0...v6.4.1";>6.4.1 
(2022-09-19)
   Bug Fixes
   
   pass integrity value (https://github.com/karma-runner/karma/commit/63d86befd3431fe8e1500e22f4f115a3762d000a";>63d86be)
   
   v6.4.0
   https://github.com/karma-runner/karma/compare/v6.3.20...v6.4.0";>6.4.0 
(2022-06-14)
   Features
   
   support SRI verification of link tags (https://github.com/karma-runner/karma/commit/dc51a2e0e9b9805f7740f52fde01bcd20adc2dfc";>dc51a2e)
   support SRI verification of script tags (https://github.com/karma-runner/karma/commit/6a54b1c2a1df8214c470b8a5cc8036912874637e";>6a54b1c)
   
   v6.3.20
   https://github.com/karma-runner/karma/compare/v6.3.19...v6.3.20";>6.3.20
 (2022-05-13)
   Bug Fixes
   
   prefer IPv4 addresses when resolving domains (https://github.com/karma-runner/karma/commit/e17698f950af83bf2b3edc540d2a3e1fb73cba59";>e17698f),
 closes https://github-redirect.dependabot.com/karma-runner/karma/issues/3730";>#3730
   
   v6.3.19
   https://github.com/karma-runner/karma/compare/v6.3.18...v6.3.19";>6.3.19
 (2022-04-19)
   Bug Fixes
   
   client: error out when opening a new tab fails (https://github.com/karma-runner/karma/commit/099b85ed0a46e37dd7cb14fc1596cbb1b3eabce9";>099b85e)
   
   v6.3.18
   https://github.com/karma-runner/karma/compare/v6.3.17...v6.3.18";>6.3.18
 (2022-04-13)
   Bug Fixes
   
   deps: upgrade socket.io to v4.4.1 (https://github.com/karma-runner/karma/commit/52a30bbc6e168333a8592c26c9f40678d6ab74ea";>52a30bb)
   
   v6.3.17
   https://github.com/karma-runner/karma/compare/v6.3.16...v6.3.17";>6.3.17
 (2022-02-28)
   Bug Fixes
   
   deps: update colors to maintained version (https://github-redirect.dependabot.com/karma-runner/karma/issues/3763";>#3763)
 (https://github.com/karma-runner/karma/commit/fca18843e7a04eeb67b86cb3cfc3db794d66f445";>fca1884)
   
   v6.3.16
   
   
   ... (truncated)
   
   
   Changelog
  

[GitHub] [nifi] dependabot[bot] commented on pull request #6882: Bump cookiejar from 2.1.3 to 2.1.4 in /nifi-registry/nifi-registry-core/nifi-registry-web-ui/src/main

2023-01-25 Thread dependabot


dependabot[bot] commented on PR #6882:
URL: https://github.com/apache/nifi/pull/6882#issuecomment-1403753638

   OK, I won't notify you again about this release, but will get in touch when 
a new version is available. If you'd rather skip all updates until the next 
major or minor version, let me know by commenting `@dependabot ignore this 
major version` or `@dependabot ignore this minor version`.
   
   If you change your mind, just re-open this PR and I'll resolve any conflicts 
on it.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscr...@nifi.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GitHub] [nifi] dependabot[bot] opened a new pull request, #6882: Bump cookiejar from 2.1.3 to 2.1.4 in /nifi-registry/nifi-registry-core/nifi-registry-web-ui/src/main

2023-01-24 Thread dependabot


dependabot[bot] opened a new pull request, #6882:
URL: https://github.com/apache/nifi/pull/6882

   Bumps [cookiejar](https://github.com/bmeck/node-cookiejar) from 2.1.3 to 
2.1.4.
   
   Commits
   
   See full diff in https://github.com/bmeck/node-cookiejar/commits";>compare view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=cookiejar&package-manager=npm_and_yarn&previous-version=2.1.3&new-version=2.1.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   - `@dependabot use these labels` will set the current labels as the default 
for future PRs for this repo and language
   - `@dependabot use these reviewers` will set the current reviewers as the 
default for future PRs for this repo and language
   - `@dependabot use these assignees` will set the current assignees as the 
default for future PRs for this repo and language
   - `@dependabot use this milestone` will set the current milestone as the 
default for future PRs for this repo and language
   
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/nifi/network/alerts).
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscr...@nifi.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org