Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump vscode-extension-tester from 7.1.0 to 7.1.1 #773

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 20, 2024

Bumps vscode-extension-tester from 7.1.0 to 7.1.1.

Release notes

Sourced from vscode-extension-tester's releases.

v7.1.1

What's Changed

New Contributors

Full Changelog: redhat-developer/vscode-extension-tester@v7.1.0...v7.1.1

Changelog

Sourced from vscode-extension-tester's changelog.

7.1.1

February 20, 2024

  • [🚀 Request] Support VS Code 1.86.2
  • [🚫 Bug] extest setup-and-run installs intel version of VSCode on mac arm
  • [🚫 Bug] Unable to run tests in sample-projects/helloworld-sample
Commits
  • 14a38b6 7.1.1 (#1142)
  • d3b7e87 build(deps-dev): update @​typescript-eslint/parser requirement from ^7.0.1 to ...
  • ab71ebe fix(helloworld-sample): Reported ESLint config errors (#1141)
  • f6298da fix: Get rid off 'require' when importing dependencies (#1140)
  • 962647e build(deps-dev): update @​typescript-eslint/eslint-plugin requirement from ^7....
  • d755742 build(deps): bump selenium-webdriver from 4.17.0 to 4.18.1 (#1139)
  • 1ca3e2d Bump @​typescript-eslint/eslint-plugin from 6.21.0 to 7.0.1 in /sample-project...
  • 7ea4220 Bump @​types/node from 18.19.15 to 18.19.17 in /sample-projects/helloworld-sam...
  • 17988e9 chore(sample-projects): Fix helloworld-sample project (#1135)
  • 6cae098 Bump vscode-extension-tester from 7.0.0 to 7.1.0 in /sample-projects/hellowor...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [vscode-extension-tester](https://github.com/redhat-developer/vscode-extension-tester) from 7.1.0 to 7.1.1.
- [Release notes](https://github.com/redhat-developer/vscode-extension-tester/releases)
- [Changelog](https://github.com/redhat-developer/vscode-extension-tester/blob/main/CHANGELOG.md)
- [Commits](redhat-developer/vscode-extension-tester@v7.1.0...v7.1.1)

---
updated-dependencies:
- dependency-name: vscode-extension-tester
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Feb 20, 2024
@dependabot dependabot bot requested a review from tiagobcx February 20, 2024 17:18
Copy link
Contributor

github-actions bot commented Feb 22, 2024

Logo
Checkmarx One – Scan Summary & Details0675c9bd-bee7-4e05-b1e3-cbbc5b6346a5

Policy Management Violations

Policy Name Rule(s) Break Build
[SAST-ML0] Not allowed NEW Sast vulnerabilities true

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH Client_DOM_XSS /media/view.js: 236 Attack Vector
HIGH Client_DOM_XSS /media/view.js: 236 Attack Vector
HIGH Client_DOM_XSS /media/view.js: 236 Attack Vector
HIGH Cxab55612e-3a56 Npm-braces-3.0.2 Vulnerable Package
HIGH Cxca84a1c2-1f12 Npm-micromatch-4.0.5 Vulnerable Package
MEDIUM Client_Privacy_Violation /media/view.js: 472 Attack Vector
MEDIUM Client_Privacy_Violation /media/view.js: 472 Attack Vector
MEDIUM Client_Privacy_Violation /media/view.js: 472 Attack Vector
MEDIUM Missing_HSTS_Header /src/resources/testProj/insecure.php: 24 Attack Vector
MEDIUM Unpinned Actions Full Length Commit SHA /dependabot-auto-merge.yml: 23 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /dependabot-auto-merge.yml: 14 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /delete-dev-releases.yml: 28 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 136 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /release.yml: 158 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /pr-label.yml: 15 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
MEDIUM Unpinned Actions Full Length Commit SHA /checkmarx-one-scan.yml: 12 Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...

Fixed Issues

Severity Issue Source File / Package
HIGH CVE-2021-3807 Npm-ansi-regex-2.1.1
HIGH Client_DOM_XSS /media/gpt.js: 122
HIGH Client_DOM_XSS /media/gpt.js: 122
HIGH Client_DOM_XSS /media/gpt.js: 122
HIGH Client_DOM_XSS /media/view.js: 247
HIGH Client_DOM_XSS /media/view.js: 247
HIGH Client_DOM_XSS /media/view.js: 247
MEDIUM CVE-2018-14040 Npm-bootstrap-4.0.0
MEDIUM CVE-2018-14041 Npm-bootstrap-4.0.0
MEDIUM CVE-2018-14042 Npm-bootstrap-4.0.0
MEDIUM CVE-2019-8331 Npm-bootstrap-4.0.0
MEDIUM CVE-2023-0842 Npm-xml2js-0.4.23
MEDIUM Client_Privacy_Violation /media/view.js: 408

@OrShamirCM OrShamirCM disabled auto-merge February 25, 2024 13:32
Copy link
Contributor Author

dependabot bot commented on behalf of github Feb 28, 2024

A newer version of vscode-extension-tester exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@OrShamirCM OrShamirCM enabled auto-merge (squash) March 5, 2024 13:06
@OrShamirCM OrShamirCM merged commit 9016d61 into main Mar 13, 2024
4 of 5 checks passed
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/vscode-extension-tester-7.1.1 branch March 13, 2024 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants