Skip to content

build(deps): bump tmpl from 1.0.4 to 1.0.5#37

Merged
MrChocolatine merged 1 commit intomasterfrom
dependabot-npm_and_yarn-tmpl-1.0.5
Sep 21, 2021
Merged

build(deps): bump tmpl from 1.0.4 to 1.0.5#37
MrChocolatine merged 1 commit intomasterfrom
dependabot-npm_and_yarn-tmpl-1.0.5

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 20, 2021

Build

Update tmpl from 1.0.4 to 1.0.5 (#37)

Fix the vulnerability GHSA-jgrx-mgxx-jf9v .

Bumps [tmpl](https://github.com/daaku/nodejs-tmpl) from 1.0.4 to 1.0.5.
- [Release notes](https://github.com/daaku/nodejs-tmpl/releases)
- [Commits](https://github.com/daaku/nodejs-tmpl/commits/v1.0.5)

---
updated-dependencies:
- dependency-name: tmpl
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot requested a review from a team as a code owner September 20, 2021 20:43
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Sep 20, 2021
@MrChocolatine MrChocolatine self-assigned this Sep 21, 2021
@MrChocolatine MrChocolatine merged commit 22e7851 into master Sep 21, 2021
@MrChocolatine MrChocolatine deleted the dependabot-npm_and_yarn-tmpl-1.0.5 branch September 21, 2021 07:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant