Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump @adobe/css-tools from 4.0.1 to 4.3.1 in /tools/az-prom-rules-converter/web-app-example #577

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Aug 30, 2023

Bumps @adobe/css-tools from 4.0.1 to 4.3.1.

Changelog

Sourced from @​adobe/css-tools's changelog.

4.3.1 / 2023-03-14

  • Fix redos vulnerability with specific crafted css string - CVE-2023-26364

4.3.0 / 2023-03-07

  • Update build tools
  • Update exports path and files

4.2.0 / 2023-02-21

4.1.0 / 2023-01-25

  • Support ESM Modules

4.0.2 / 2023-01-12

  • #71 : @​import does not work if url contains ';'
  • #77 : Regression in selector parsing: Attribute selectors not parsed correctly
Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot requested a review from a team as a code owner August 30, 2023 03:36
@dependabot dependabot bot added javascript Pull requests that update Javascript code OSS dependency Indicates there is work on OSS side to complete this labels Aug 30, 2023
@github-actions
Copy link

github-actions bot commented Sep 6, 2023

This PR is stale because it has been open 7 days with no activity. Remove stale label or comment or this will be closed in 5 days.

@github-actions
Copy link

This PR was closed because it has been stalled for 12 days with no activity.

@github-actions github-actions bot closed this Sep 11, 2023
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Sep 11, 2023

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/npm_and_yarn/tools/az-prom-rules-converter/web-app-example/adobe/css-tools-4.3.1 branch September 11, 2023 10:34
@vishiy vishiy restored the dependabot/npm_and_yarn/tools/az-prom-rules-converter/web-app-example/adobe/css-tools-4.3.1 branch September 21, 2023 19:20
@vishiy vishiy reopened this Sep 21, 2023
Bumps [@adobe/css-tools](https://github.com/adobe/css-tools) from 4.0.1 to 4.3.1.
- [Changelog](https://github.com/adobe/css-tools/blob/main/History.md)
- [Commits](https://github.com/adobe/css-tools/commits)

---
updated-dependencies:
- dependency-name: "@adobe/css-tools"
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/tools/az-prom-rules-converter/web-app-example/adobe/css-tools-4.3.1 branch from eaf9c5a to 1976f46 Compare September 21, 2023 19:21
@vishiy
Copy link
Contributor

vishiy commented Sep 21, 2023

@moshemal - can you please review this PR ?

@github-actions
Copy link

This PR is stale because it has been open 7 days with no activity. Remove stale label or comment or this will be closed in 5 days.

@vishiy
Copy link
Contributor

vishiy commented Sep 30, 2023

@moshemal - can u pls look and approve this PR ?

@vishiy vishiy merged commit 0dc6fb4 into main Oct 6, 2023
10 of 12 checks passed
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/tools/az-prom-rules-converter/web-app-example/adobe/css-tools-4.3.1 branch October 6, 2023 04:48
vishiy added a commit that referenced this pull request Oct 6, 2023
* Add cluster scope to alert rule groups for linking them with UX (#600)

* Removing duplicate alerts from ci recommended alerts

* Remove test branch

* Remove preview keyword from policy readme

* Add cluster id scope to rule groups for alerts to be linked to UX

* adding terraform update

* Add cicd and prod near ring cluster monitoring for managed prometheus (#602)

* Removing duplicate alerts from ci recommended alerts

* Remove test branch

* Remove preview keyword from policy readme

* Add cicd and prod near ring cluster monitoring for managed prometheus

* Make single file for alerts and update dashboard to include unit in memory

* Replace label for cluster name with clusterName property

* Add telemetry for scrape interval (#614)

* Removing duplicate alerts from ci recommended alerts

* Remove test branch

* Remove preview keyword from policy readme

* Add telemetry for scrape interval hash

* remove branch name

* Upgrade dependencies (#616)

* upgrade all dependencies but collector

* update golang

* Update CVEs

* update config

* remove branch

* make build fail when trivy fails

* fix trivy scan for image not found for PRs

* windows fix for replicaset collecting windows data (#620)

* fix: remove uneeded windows scrape config in replicaset

* .

* .

* .

* revert windows telegraf update

* missed end

* remove examplar disablement for windows

* bin place me_win configs

---------

Co-authored-by: Grace Wehner <[email protected]>
Co-authored-by: bragi92 <[email protected]>

* Bug fix- update cert thumbprint to latest ame prod cert (#615)

* Removing duplicate alerts from ci recommended alerts

* Remove test branch

* Remove preview keyword from policy readme

* Bug fix- update cert thumbprint for image signing  to latest ame prod cert

* Fix $ substitution issue in relabel and metric relabel config (#618)

* dollar fix for node name and node ip

* test $ replacement

* clean up build

* Bump @adobe/css-tools in /tools/az-prom-rules-converter/web-app-example (#577)

Bumps [@adobe/css-tools](https://github.com/adobe/css-tools) from 4.0.1 to 4.3.1.
- [Changelog](https://github.com/adobe/css-tools/blob/main/History.md)
- [Commits](https://github.com/adobe/css-tools/commits)

---
updated-dependencies:
- dependency-name: "@adobe/css-tools"
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: Sohamdg081992 <[email protected]>
Co-authored-by: Grace Wehner <[email protected]>
Co-authored-by: bragi92 <[email protected]>
Co-authored-by: rashmichandrashekar <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
vishiy added a commit that referenced this pull request Oct 6, 2023
…elcollector/fluent-bit/src (#608)

* Bump github.com/prometheus/client_golang

Bumps [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) from 1.16.0 to 1.17.0.
- [Release notes](https://github.com/prometheus/client_golang/releases)
- [Changelog](https://github.com/prometheus/client_golang/blob/v1.17.0/CHANGELOG.md)
- [Commits](prometheus/client_golang@v1.16.0...v1.17.0)

---
updated-dependencies:
- dependency-name: github.com/prometheus/client_golang
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>

* merge from main (#622)

* Add cluster scope to alert rule groups for linking them with UX (#600)

* Removing duplicate alerts from ci recommended alerts

* Remove test branch

* Remove preview keyword from policy readme

* Add cluster id scope to rule groups for alerts to be linked to UX

* adding terraform update

* Add cicd and prod near ring cluster monitoring for managed prometheus (#602)

* Removing duplicate alerts from ci recommended alerts

* Remove test branch

* Remove preview keyword from policy readme

* Add cicd and prod near ring cluster monitoring for managed prometheus

* Make single file for alerts and update dashboard to include unit in memory

* Replace label for cluster name with clusterName property

* Add telemetry for scrape interval (#614)

* Removing duplicate alerts from ci recommended alerts

* Remove test branch

* Remove preview keyword from policy readme

* Add telemetry for scrape interval hash

* remove branch name

* Upgrade dependencies (#616)

* upgrade all dependencies but collector

* update golang

* Update CVEs

* update config

* remove branch

* make build fail when trivy fails

* fix trivy scan for image not found for PRs

* windows fix for replicaset collecting windows data (#620)

* fix: remove uneeded windows scrape config in replicaset

* .

* .

* .

* revert windows telegraf update

* missed end

* remove examplar disablement for windows

* bin place me_win configs

---------

Co-authored-by: Grace Wehner <[email protected]>
Co-authored-by: bragi92 <[email protected]>

* Bug fix- update cert thumbprint to latest ame prod cert (#615)

* Removing duplicate alerts from ci recommended alerts

* Remove test branch

* Remove preview keyword from policy readme

* Bug fix- update cert thumbprint for image signing  to latest ame prod cert

* Fix $ substitution issue in relabel and metric relabel config (#618)

* dollar fix for node name and node ip

* test $ replacement

* clean up build

* Bump @adobe/css-tools in /tools/az-prom-rules-converter/web-app-example (#577)

Bumps [@adobe/css-tools](https://github.com/adobe/css-tools) from 4.0.1 to 4.3.1.
- [Changelog](https://github.com/adobe/css-tools/blob/main/History.md)
- [Commits](https://github.com/adobe/css-tools/commits)

---
updated-dependencies:
- dependency-name: "@adobe/css-tools"
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: Sohamdg081992 <[email protected]>
Co-authored-by: Grace Wehner <[email protected]>
Co-authored-by: bragi92 <[email protected]>
Co-authored-by: rashmichandrashekar <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* remove private branch

* Update RELEASENOTES.md

* Update VERSION

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Vishwanath <[email protected]>
Co-authored-by: Sohamdg081992 <[email protected]>
Co-authored-by: Grace Wehner <[email protected]>
Co-authored-by: bragi92 <[email protected]>
Co-authored-by: rashmichandrashekar <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
javascript Pull requests that update Javascript code OSS dependency Indicates there is work on OSS side to complete this size/XS
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants