Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 20, 2022

Bumps simple-git from 2.48.0 to 3.7.0.

Release notes

Sourced from simple-git's releases.

simple-git@3.7.0

Minor Changes

  • fa2c7f7: Enable the use of types when loading with module-resolution

Patch Changes

  • 3805f6b: Timeout plugin no longer keeps short lived processes alive until timeout is hit

simple-git@3.6.0

Minor Changes

  • f2fc5c9: Show full commit hash in a CommitResult, prior to this change git.commit would result in a partial hash in the commit property if core.abbrev is unset or has a value under 40. Following this change the commit property will contain the full commit hash.

Patch Changes

  • c4a2a13: chore(deps): bump minimist from 1.2.5 to 1.2.6

simple-git@3.5.0

Minor Changes

  • 2040de6: Resolves potential command injection vulnerability by preventing use of --upload-pack in git.clone

simple-git@3.4.0

Minor Changes

  • ed412ef: Use null separators in git.status to allow for non-ascii file names

simple-git@3.3.0

Minor Changes

  • d119ec4: Resolves potential command injection vulnerability by preventing use of --upload-pack in git.fetch

simple-git@3.2.6

Patch Changes

  • 80651d5: Resolve issue in prePublish script

simple-git@3.2.4

Patch Changes

  • d35987b: Release with changesets

simple-git simple-git-v3.1.1

Bug Fixes

  • specify repository with directory identifier to be discoverable within monorepo (655e23c)

... (truncated)

Changelog

Sourced from simple-git's changelog.

3.7.0

Minor Changes

  • fa2c7f7: Enable the use of types when loading with module-resolution

Patch Changes

  • 3805f6b: Timeout plugin no longer keeps short lived processes alive until timeout is hit

3.6.0

Minor Changes

  • f2fc5c9: Show full commit hash in a CommitResult, prior to this change git.commit would result in a partial hash in the commit property if core.abbrev is unset or has a value under 40. Following this change the commit property will contain the full commit hash.

Patch Changes

  • c4a2a13: chore(deps): bump minimist from 1.2.5 to 1.2.6

3.5.0

Minor Changes

  • 2040de6: Resolves potential command injection vulnerability by preventing use of --upload-pack in git.clone

3.4.0

Minor Changes

  • ed412ef: Use null separators in git.status to allow for non-ascii file names

3.3.0

Minor Changes

  • d119ec4: Resolves potential command injection vulnerability by preventing use of --upload-pack in git.fetch

3.2.6

Patch Changes

  • 80651d5: Resolve issue in prePublish script

3.2.5

Patch Changes

  • ac4f38f: Show readme in published package.

... (truncated)

Commits
  • 39abae0 Version Packages
  • 2182af4 Merge pull request #787 from steveukx/feat/export-types
  • fa2c7f7 Add Typescript types to the simple-git exports, for use when importing thro...
  • 463e193 Clear timeout upon stop to avoid hanging the process
  • c8f2251 Update CHANGELOG.md
  • 25667fe Version Packages
  • c88703d Use import type annotations in the executors.
  • f2fc5c9 Override local configuration for git.commit to show full commit hashes when...
  • 4fc3747 Version Packages
  • 2040de6 Prevent use of --upload-pack as a command in git.clone to avoid potential...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [simple-git](https://github.com/steveukx/git-js/tree/HEAD/simple-git) from 2.48.0 to 3.7.0.
- [Release notes](https://github.com/steveukx/git-js/releases)
- [Changelog](https://github.com/steveukx/git-js/blob/main/simple-git/CHANGELOG.md)
- [Commits](https://github.com/steveukx/git-js/commits/simple-git@3.7.0/simple-git)

---
updated-dependencies:
- dependency-name: simple-git
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from Xunnamius as a code owner April 20, 2022 10:36
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 20, 2022
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Apr 25, 2022

Superseded by #86.

@dependabot dependabot bot closed this Apr 25, 2022
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/simple-git-3.7.0 branch April 25, 2022 10:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant