Conversation
|
New dependency changes detected. Learn more about Socket for GitHub ↗︎ 🚨 Potential security issues found in this pull request. To accept the risk, merge this PR and you will not be notified again. Bot CommandsTo ignore an alert, reply with a comment starting with
🫣 Native codeContains native code which could be a vector to obscure malicious code, and generally decrease the likelihood of reproducible or reliable installs. Ensure that native code bindings are expected. Consumers may consider pure JS and functionally similar alternatives to avoid the challenges and risks associated with native code bindings.
Pull request alert summary
📊 Modified Dependency Overview:
|
07cbd61 to
67b94bb
Compare
67b94bb to
d7a0d19
Compare
d7a0d19 to
40fec2f
Compare
40fec2f to
b90e5b1
Compare
e34cdde to
9c44033
Compare
d420cd8 to
330d6eb
Compare
330d6eb to
8b0adf3
Compare
3d47dbe to
1a0c81d
Compare
1a0c81d to
96aad6d
Compare
96aad6d to
a74d1ce
Compare
371a885 to
099f768
Compare
7bf6359 to
82e403c
Compare
Bumps [postcss](https://github.com/postcss/postcss) and [parcel](https://github.com/parcel-bundler/parcel). These dependencies needed to be updated together. Removes `postcss` Updates `parcel` from 1.12.4 to 2.7.0 - [Release notes](https://github.com/parcel-bundler/parcel/releases) - [Changelog](https://github.com/parcel-bundler/parcel/blob/v2/CHANGELOG.md) - [Commits](https://github.com/parcel-bundler/parcel/compare/parcel-bundler@1.12.4...v2.7.0) --- updated-dependencies: - dependency-name: postcss dependency-type: indirect - dependency-name: parcel dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
82e403c to
db8ab73
Compare
|
Superseded by #323. |
Bumps postcss and parcel. These dependencies needed to be updated together.
Removes
postcssUpdates
parcelfrom 1.12.4 to 2.7.0Release notes
Sourced from parcel's releases.
... (truncated)
Changelog
Sourced from parcel's changelog.
... (truncated)
Commits
5f095fdv2.7.0000d332Changelog for v2.7.01a96d6dUse placeholder expression when replacing unused symbols (#8358)a22164cLint (#8359)9012616Add support for errorRecovery option in@parcel/transformer-css(#8352)56e621eVS Code Extension for Parcel (#8139)fca5c8cAdd multi module compilation for elm (#8076)128e072Bump terser from 5.7.2 to 5.14.2 (#8322)565e5f0Bump node-forge from 1.2.1 to 1.3.0 (#8271)085a7aaallow cjs config files on type module projects (#8253)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.